Linux Audio

Check our new training course

Loading...
v3.1
 
   1/*
   2 *   fs/cifs/connect.c
   3 *
   4 *   Copyright (C) International Business Machines  Corp., 2002,2009
   5 *   Author(s): Steve French (sfrench@us.ibm.com)
   6 *
   7 *   This library is free software; you can redistribute it and/or modify
   8 *   it under the terms of the GNU Lesser General Public License as published
   9 *   by the Free Software Foundation; either version 2.1 of the License, or
  10 *   (at your option) any later version.
  11 *
  12 *   This library is distributed in the hope that it will be useful,
  13 *   but WITHOUT ANY WARRANTY; without even the implied warranty of
  14 *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See
  15 *   the GNU Lesser General Public License for more details.
  16 *
  17 *   You should have received a copy of the GNU Lesser General Public License
  18 *   along with this library; if not, write to the Free Software
  19 *   Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  20 */
  21#include <linux/fs.h>
  22#include <linux/net.h>
  23#include <linux/string.h>
 
 
  24#include <linux/list.h>
  25#include <linux/wait.h>
  26#include <linux/slab.h>
  27#include <linux/pagemap.h>
  28#include <linux/ctype.h>
  29#include <linux/utsname.h>
  30#include <linux/mempool.h>
  31#include <linux/delay.h>
  32#include <linux/completion.h>
  33#include <linux/kthread.h>
  34#include <linux/pagevec.h>
  35#include <linux/freezer.h>
  36#include <linux/namei.h>
  37#include <asm/uaccess.h>
 
  38#include <asm/processor.h>
  39#include <linux/inet.h>
 
 
  40#include <net/ipv6.h>
 
 
  41#include "cifspdu.h"
  42#include "cifsglob.h"
  43#include "cifsproto.h"
  44#include "cifs_unicode.h"
  45#include "cifs_debug.h"
  46#include "cifs_fs_sb.h"
  47#include "ntlmssp.h"
  48#include "nterr.h"
  49#include "rfc1002pdu.h"
  50#include "fscache.h"
  51
  52#define CIFS_PORT 445
  53#define RFC1001_PORT 139
  54
  55/* SMB echo "timeout" -- FIXME: tunable? */
  56#define SMB_ECHO_INTERVAL (60 * HZ)
 
 
 
  57
  58extern mempool_t *cifs_req_poolp;
 
  59
  60/* FIXME: should these be tunable? */
  61#define TLINK_ERROR_EXPIRE	(1 * HZ)
  62#define TLINK_IDLE_EXPIRE	(600 * HZ)
  63
 
 
 
  64static int ip_connect(struct TCP_Server_Info *server);
  65static int generic_ip_connect(struct TCP_Server_Info *server);
  66static void tlink_rb_insert(struct rb_root *root, struct tcon_link *new_tlink);
  67static void cifs_prune_tlinks(struct work_struct *work);
  68static int cifs_setup_volume_info(struct smb_vol *volume_info, char *mount_data,
  69					const char *devname);
  70
  71/*
  72 * cifs tcp session reconnection
 
  73 *
  74 * mark tcp session as reconnecting so temporarily locked
  75 * mark all smb sessions as reconnecting for tcp session
  76 * reconnect tcp session
  77 * wake up waiters on reconnection? - (not needed currently)
  78 */
  79static int
  80cifs_reconnect(struct TCP_Server_Info *server)
  81{
  82	int rc = 0;
  83	struct list_head *tmp, *tmp2;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
  84	struct cifs_ses *ses;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
  85	struct cifs_tcon *tcon;
  86	struct mid_q_entry *mid_entry;
  87	struct list_head retry_list;
  88
  89	spin_lock(&GlobalMid_Lock);
  90	if (server->tcpStatus == CifsExiting) {
  91		/* the demux thread will exit normally
  92		next time through the loop */
  93		spin_unlock(&GlobalMid_Lock);
  94		return rc;
  95	} else
  96		server->tcpStatus = CifsNeedReconnect;
  97	spin_unlock(&GlobalMid_Lock);
  98	server->maxBuf = 0;
  99
 100	cFYI(1, "Reconnecting tcp session");
 101
 102	/* before reconnecting the tcp session, mark the smb session (uid)
 103		and the tid bad so they are not used until reconnected */
 104	cFYI(1, "%s: marking sessions and tcons for reconnect", __func__);
 105	spin_lock(&cifs_tcp_ses_lock);
 106	list_for_each(tmp, &server->smb_ses_list) {
 107		ses = list_entry(tmp, struct cifs_ses, smb_ses_list);
 108		ses->need_reconnect = true;
 109		ses->ipc_tid = 0;
 110		list_for_each(tmp2, &ses->tcon_list) {
 111			tcon = list_entry(tmp2, struct cifs_tcon, tcon_list);
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 112			tcon->need_reconnect = true;
 
 113		}
 
 
 
 
 
 
 
 114	}
 115	spin_unlock(&cifs_tcp_ses_lock);
 
 
 
 
 
 
 
 
 
 
 116
 117	/* do not want to be sending data on a socket we are freeing */
 118	cFYI(1, "%s: tearing down socket", __func__);
 119	mutex_lock(&server->srv_mutex);
 120	if (server->ssocket) {
 121		cFYI(1, "State: 0x%x Flags: 0x%lx", server->ssocket->state,
 122			server->ssocket->flags);
 123		kernel_sock_shutdown(server->ssocket, SHUT_WR);
 124		cFYI(1, "Post shutdown state: 0x%x Flags: 0x%lx",
 125			server->ssocket->state,
 126			server->ssocket->flags);
 127		sock_release(server->ssocket);
 128		server->ssocket = NULL;
 129	}
 130	server->sequence_number = 0;
 131	server->session_estab = false;
 132	kfree(server->session_key.response);
 133	server->session_key.response = NULL;
 134	server->session_key.len = 0;
 135	server->lstrp = jiffies;
 136	mutex_unlock(&server->srv_mutex);
 137
 138	/* mark submitted MIDs for retry and issue callback */
 139	INIT_LIST_HEAD(&retry_list);
 140	cFYI(1, "%s: moving mids to private list", __func__);
 141	spin_lock(&GlobalMid_Lock);
 142	list_for_each_safe(tmp, tmp2, &server->pending_mid_q) {
 143		mid_entry = list_entry(tmp, struct mid_q_entry, qhead);
 144		if (mid_entry->midState == MID_REQUEST_SUBMITTED)
 145			mid_entry->midState = MID_RETRY_NEEDED;
 146		list_move(&mid_entry->qhead, &retry_list);
 147	}
 148	spin_unlock(&GlobalMid_Lock);
 149
 150	cFYI(1, "%s: issuing mid callbacks", __func__);
 151	list_for_each_safe(tmp, tmp2, &retry_list) {
 152		mid_entry = list_entry(tmp, struct mid_q_entry, qhead);
 153		list_del_init(&mid_entry->qhead);
 154		mid_entry->callback(mid_entry);
 155	}
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 156
 157	do {
 158		try_to_freeze();
 
 159
 160		/* we should try only the port we connected to before */
 161		rc = generic_ip_connect(server);
 
 
 
 
 
 
 
 
 162		if (rc) {
 163			cFYI(1, "reconnect error %d", rc);
 
 164			msleep(3000);
 165		} else {
 166			atomic_inc(&tcpSesReconnectCount);
 167			spin_lock(&GlobalMid_Lock);
 
 168			if (server->tcpStatus != CifsExiting)
 169				server->tcpStatus = CifsNeedNegotiate;
 170			spin_unlock(&GlobalMid_Lock);
 
 
 
 171		}
 172	} while (server->tcpStatus == CifsNeedReconnect);
 173
 
 
 
 
 
 
 174	return rc;
 175}
 176
 177/*
 178	return codes:
 179		0 	not a transact2, or all data present
 180		>0 	transact2 with that much data missing
 181		-EINVAL = invalid transact2
 182
 183 */
 184static int check2ndT2(struct smb_hdr *pSMB, unsigned int maxBufSize)
 185{
 186	struct smb_t2_rsp *pSMBt;
 187	int remaining;
 188	__u16 total_data_size, data_in_this_rsp;
 189
 190	if (pSMB->Command != SMB_COM_TRANSACTION2)
 191		return 0;
 192
 193	/* check for plausible wct, bcc and t2 data and parm sizes */
 194	/* check for parm and data offset going beyond end of smb */
 195	if (pSMB->WordCount != 10) { /* coalesce_t2 depends on this */
 196		cFYI(1, "invalid transact2 word count");
 197		return -EINVAL;
 198	}
 199
 200	pSMBt = (struct smb_t2_rsp *)pSMB;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 201
 202	total_data_size = get_unaligned_le16(&pSMBt->t2_rsp.TotalDataCount);
 203	data_in_this_rsp = get_unaligned_le16(&pSMBt->t2_rsp.DataCount);
 204
 205	if (total_data_size == data_in_this_rsp)
 206		return 0;
 207	else if (total_data_size < data_in_this_rsp) {
 208		cFYI(1, "total data %d smaller than data in frame %d",
 209			total_data_size, data_in_this_rsp);
 210		return -EINVAL;
 211	}
 212
 213	remaining = total_data_size - data_in_this_rsp;
 214
 215	cFYI(1, "missing %d bytes from transact2, check next response",
 216		remaining);
 217	if (total_data_size > maxBufSize) {
 218		cERROR(1, "TotalDataSize %d is over maximum buffer %d",
 219			total_data_size, maxBufSize);
 220		return -EINVAL;
 
 
 
 
 
 
 221	}
 222	return remaining;
 223}
 224
 225static int coalesce_t2(struct smb_hdr *psecond, struct smb_hdr *pTargetSMB)
 226{
 227	struct smb_t2_rsp *pSMB2 = (struct smb_t2_rsp *)psecond;
 228	struct smb_t2_rsp *pSMBt  = (struct smb_t2_rsp *)pTargetSMB;
 229	char *data_area_of_target;
 230	char *data_area_of_buf2;
 231	int remaining;
 232	unsigned int byte_count, total_in_buf;
 233	__u16 total_data_size, total_in_buf2;
 234
 235	total_data_size = get_unaligned_le16(&pSMBt->t2_rsp.TotalDataCount);
 236
 237	if (total_data_size !=
 238	    get_unaligned_le16(&pSMB2->t2_rsp.TotalDataCount))
 239		cFYI(1, "total data size of primary and secondary t2 differ");
 240
 241	total_in_buf = get_unaligned_le16(&pSMBt->t2_rsp.DataCount);
 242
 243	remaining = total_data_size - total_in_buf;
 244
 245	if (remaining < 0)
 246		return -EPROTO;
 
 
 
 
 
 
 
 
 
 
 247
 248	if (remaining == 0) /* nothing to do, ignore */
 249		return 0;
 250
 251	total_in_buf2 = get_unaligned_le16(&pSMB2->t2_rsp.DataCount);
 252	if (remaining < total_in_buf2) {
 253		cFYI(1, "transact2 2nd response contains too much data");
 254	}
 
 
 255
 256	/* find end of first SMB data area */
 257	data_area_of_target = (char *)&pSMBt->hdr.Protocol +
 258				get_unaligned_le16(&pSMBt->t2_rsp.DataOffset);
 259	/* validate target area */
 260
 261	data_area_of_buf2 = (char *)&pSMB2->hdr.Protocol +
 262				get_unaligned_le16(&pSMB2->t2_rsp.DataOffset);
 
 263
 264	data_area_of_target += total_in_buf;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 265
 266	/* copy second buffer into end of first buffer */
 267	total_in_buf += total_in_buf2;
 268	/* is the result too big for the field? */
 269	if (total_in_buf > USHRT_MAX)
 270		return -EPROTO;
 271	put_unaligned_le16(total_in_buf, &pSMBt->t2_rsp.DataCount);
 272
 273	/* fix up the BCC */
 274	byte_count = get_bcc(pTargetSMB);
 275	byte_count += total_in_buf2;
 276	/* is the result too big for the field? */
 277	if (byte_count > USHRT_MAX)
 278		return -EPROTO;
 279	put_bcc(byte_count, pTargetSMB);
 280
 281	byte_count = be32_to_cpu(pTargetSMB->smb_buf_length);
 282	byte_count += total_in_buf2;
 283	/* don't allow buffer to overflow */
 284	if (byte_count > CIFSMaxBufSize)
 285		return -ENOBUFS;
 286	pTargetSMB->smb_buf_length = cpu_to_be32(byte_count);
 287
 288	memcpy(data_area_of_target, data_area_of_buf2, total_in_buf2);
 
 
 
 
 
 
 
 289
 290	if (remaining == total_in_buf2) {
 291		cFYI(1, "found the last secondary response");
 292		return 0; /* we are done */
 293	} else /* more responses to go */
 294		return 1;
 295}
 
 
 
 
 
 
 296
 297static void
 298cifs_echo_request(struct work_struct *work)
 299{
 300	int rc;
 301	struct TCP_Server_Info *server = container_of(work,
 302					struct TCP_Server_Info, echo.work);
 303
 304	/*
 305	 * We cannot send an echo until the NEGOTIATE_PROTOCOL request is
 306	 * done, which is indicated by maxBuf != 0. Also, no need to ping if
 307	 * we got a response recently
 308	 */
 309	if (server->maxBuf == 0 ||
 310	    time_before(jiffies, server->lstrp + SMB_ECHO_INTERVAL - HZ))
 
 
 
 
 311		goto requeue_echo;
 312
 313	rc = CIFSSMBEcho(server);
 314	if (rc)
 315		cFYI(1, "Unable to send echo request to server: %s",
 316			server->hostname);
 
 
 
 317
 318requeue_echo:
 319	queue_delayed_work(system_nrt_wq, &server->echo, SMB_ECHO_INTERVAL);
 320}
 321
 322static bool
 323allocate_buffers(char **bigbuf, char **smallbuf, unsigned int size,
 324		 bool is_large_buf)
 325{
 326	char *bbuf = *bigbuf, *sbuf = *smallbuf;
 327
 328	if (bbuf == NULL) {
 329		bbuf = (char *)cifs_buf_get();
 330		if (!bbuf) {
 331			cERROR(1, "No memory for large SMB response");
 332			msleep(3000);
 333			/* retry will check if exiting */
 334			return false;
 335		}
 336	} else if (is_large_buf) {
 337		/* we are reusing a dirty large buf, clear its start */
 338		memset(bbuf, 0, size);
 339	}
 340
 341	if (sbuf == NULL) {
 342		sbuf = (char *)cifs_small_buf_get();
 343		if (!sbuf) {
 344			cERROR(1, "No memory for SMB response");
 345			msleep(1000);
 346			/* retry will check if exiting */
 347			return false;
 348		}
 349		/* beginning of smb buffer is cleared in our buf_get */
 350	} else {
 351		/* if existing small buf clear beginning */
 352		memset(sbuf, 0, size);
 353	}
 354
 355	*bigbuf = bbuf;
 356	*smallbuf = sbuf;
 357
 358	return true;
 359}
 360
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 361static int
 362read_from_socket(struct TCP_Server_Info *server, struct msghdr *smb_msg,
 363		 struct kvec *iov, unsigned int to_read,
 364		 unsigned int *ptotal_read, bool is_header_read)
 365{
 366	int length, rc = 0;
 367	unsigned int total_read;
 368	char *buf = iov->iov_base;
 369
 370	for (total_read = 0; total_read < to_read; total_read += length) {
 371		length = kernel_recvmsg(server->ssocket, smb_msg, iov, 1,
 372					to_read - total_read, 0);
 
 
 
 
 
 
 
 
 
 
 
 373		if (server->tcpStatus == CifsExiting) {
 374			/* then will exit */
 375			rc = 2;
 376			break;
 377		} else if (server->tcpStatus == CifsNeedReconnect) {
 378			cifs_reconnect(server);
 379			/* Reconnect wakes up rspns q */
 380			/* Now we will reread sock */
 381			rc = 1;
 382			break;
 383		} else if (length == -ERESTARTSYS ||
 384			   length == -EAGAIN ||
 385			   length == -EINTR) {
 
 
 386			/*
 387			 * Minimum sleep to prevent looping, allowing socket
 388			 * to clear and app threads to set tcpStatus
 389			 * CifsNeedReconnect if server hung.
 390			 */
 391			usleep_range(1000, 2000);
 392			length = 0;
 393			if (!is_header_read)
 394				continue;
 395			/* Special handling for header read */
 396			if (total_read) {
 397				iov->iov_base = (to_read - total_read) +
 398						buf;
 399				iov->iov_len = to_read - total_read;
 400				smb_msg->msg_control = NULL;
 401				smb_msg->msg_controllen = 0;
 402				rc = 3;
 403			} else
 404				rc = 1;
 405			break;
 406		} else if (length <= 0) {
 407			cERROR(1, "Received no data, expecting %d",
 408			       to_read - total_read);
 409			cifs_reconnect(server);
 410			rc = 1;
 411			break;
 412		}
 413	}
 
 
 414
 415	*ptotal_read = total_read;
 416	return rc;
 
 
 
 
 
 
 
 417}
 418
 419static bool
 420check_rfc1002_header(struct TCP_Server_Info *server, char *buf)
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 421{
 422	char temp = *buf;
 423	unsigned int pdu_length = be32_to_cpu(
 424				((struct smb_hdr *)buf)->smb_buf_length);
 
 
 
 425
 
 
 
 426	/*
 427	 * The first byte big endian of the length field,
 428	 * is actually not part of the length but the type
 429	 * with the most common, zero, as regular data.
 430	 */
 431	if (temp == (char) RFC1002_SESSION_KEEP_ALIVE) {
 432		return false;
 433	} else if (temp == (char)RFC1002_POSITIVE_SESSION_RESPONSE) {
 434		cFYI(1, "Good RFC 1002 session rsp");
 435		return false;
 436	} else if (temp == (char)RFC1002_NEGATIVE_SESSION_RESPONSE) {
 
 
 
 
 
 437		/*
 438		 * We get this from Windows 98 instead of an error on
 439		 * SMB negprot response.
 440		 */
 441		cFYI(1, "Negative RFC1002 Session Response Error 0x%x)",
 442			pdu_length);
 443		/* give server a second to clean up */
 444		msleep(1000);
 445		/*
 446		 * Always try 445 first on reconnect since we get NACK
 447		 * on some if we ever connected to port 139 (the NACK
 448		 * is since we do not begin with RFC1001 session
 449		 * initialize frame).
 450		 */
 451		cifs_set_port((struct sockaddr *)
 452				&server->dstaddr, CIFS_PORT);
 453		cifs_reconnect(server);
 454		wake_up(&server->response_q);
 455		return false;
 456	} else if (temp != (char) 0) {
 457		cERROR(1, "Unknown RFC 1002 frame");
 458		cifs_dump_mem(" Received Data: ", buf, 4);
 459		cifs_reconnect(server);
 460		return false;
 461	}
 462
 463	/* else we have an SMB response */
 464	if ((pdu_length > CIFSMaxBufSize + MAX_CIFS_HDR_SIZE - 4) ||
 465	    (pdu_length < sizeof(struct smb_hdr) - 1 - 4)) {
 466		cERROR(1, "Invalid size SMB length %d pdu_length %d",
 467		       4, pdu_length+4);
 468		cifs_reconnect(server);
 469		wake_up(&server->response_q);
 470		return false;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 471	}
 
 472
 473	return true;
 
 
 
 
 
 
 
 
 
 
 
 474}
 475
 476static struct mid_q_entry *
 477find_cifs_mid(struct TCP_Server_Info *server, struct smb_hdr *buf,
 478	      int *length, bool is_large_buf, bool *is_multi_rsp, char **bigbuf)
 479{
 480	struct mid_q_entry *mid = NULL, *tmp_mid, *ret = NULL;
 481
 482	spin_lock(&GlobalMid_Lock);
 483	list_for_each_entry_safe(mid, tmp_mid, &server->pending_mid_q, qhead) {
 484		if (mid->mid != buf->Mid ||
 485		    mid->midState != MID_REQUEST_SUBMITTED ||
 486		    mid->command != buf->Command)
 487			continue;
 
 
 
 
 
 
 
 
 488
 489		if (*length == 0 && check2ndT2(buf, server->maxBuf) > 0) {
 490			/* We have a multipart transact2 resp */
 491			*is_multi_rsp = true;
 492			if (mid->resp_buf) {
 493				/* merge response - fix up 1st*/
 494				*length = coalesce_t2(buf, mid->resp_buf);
 495				if (*length > 0) {
 496					*length = 0;
 497					mid->multiRsp = true;
 498					break;
 499				}
 500				/* All parts received or packet is malformed. */
 501				mid->multiEnd = true;
 502				goto multi_t2_fnd;
 503			}
 504			if (!is_large_buf) {
 505				/*FIXME: switch to already allocated largebuf?*/
 506				cERROR(1, "1st trans2 resp needs bigbuf");
 507			} else {
 508				/* Have first buffer */
 509				mid->resp_buf = buf;
 510				mid->largeBuf = true;
 511				*bigbuf = NULL;
 512			}
 513			break;
 
 
 514		}
 515		mid->resp_buf = buf;
 516		mid->largeBuf = is_large_buf;
 517multi_t2_fnd:
 518		if (*length == 0)
 519			mid->midState = MID_RESPONSE_RECEIVED;
 520		else
 521			mid->midState = MID_RESPONSE_MALFORMED;
 522#ifdef CONFIG_CIFS_STATS2
 523		mid->when_received = jiffies;
 524#endif
 525		list_del_init(&mid->qhead);
 526		ret = mid;
 527		break;
 528	}
 529	spin_unlock(&GlobalMid_Lock);
 530
 531	return ret;
 
 
 
 
 
 
 
 
 
 
 
 
 532}
 533
 
 534static void clean_demultiplex_info(struct TCP_Server_Info *server)
 535{
 536	int length;
 537
 538	/* take it off the list, if it's not already */
 539	spin_lock(&cifs_tcp_ses_lock);
 540	list_del_init(&server->tcp_ses_list);
 541	spin_unlock(&cifs_tcp_ses_lock);
 542
 543	spin_lock(&GlobalMid_Lock);
 
 
 
 544	server->tcpStatus = CifsExiting;
 545	spin_unlock(&GlobalMid_Lock);
 546	wake_up_all(&server->response_q);
 547
 548	/*
 549	 * Check if we have blocked requests that need to free. Note that
 550	 * cifs_max_pending is normally 50, but can be set at module install
 551	 * time to as little as two.
 552	 */
 553	spin_lock(&GlobalMid_Lock);
 554	if (atomic_read(&server->inFlight) >= cifs_max_pending)
 555		atomic_set(&server->inFlight, cifs_max_pending - 1);
 556	/*
 557	 * We do not want to set the max_pending too low or we could end up
 558	 * with the counter going negative.
 559	 */
 560	spin_unlock(&GlobalMid_Lock);
 561	/*
 562	 * Although there should not be any requests blocked on this queue it
 563	 * can not hurt to be paranoid and try to wake up requests that may
 564	 * haven been blocked when more than 50 at time were on the wire to the
 565	 * same server - they now will see the session is in exit state and get
 566	 * out of SendReceive.
 567	 */
 568	wake_up_all(&server->request_q);
 569	/* give those requests time to exit */
 570	msleep(125);
 571
 
 572	if (server->ssocket) {
 573		sock_release(server->ssocket);
 574		server->ssocket = NULL;
 575	}
 576
 577	if (!list_empty(&server->pending_mid_q)) {
 578		struct list_head dispose_list;
 579		struct mid_q_entry *mid_entry;
 580		struct list_head *tmp, *tmp2;
 581
 582		INIT_LIST_HEAD(&dispose_list);
 583		spin_lock(&GlobalMid_Lock);
 584		list_for_each_safe(tmp, tmp2, &server->pending_mid_q) {
 585			mid_entry = list_entry(tmp, struct mid_q_entry, qhead);
 586			cFYI(1, "Clearing mid 0x%x", mid_entry->mid);
 587			mid_entry->midState = MID_SHUTDOWN;
 
 588			list_move(&mid_entry->qhead, &dispose_list);
 
 589		}
 590		spin_unlock(&GlobalMid_Lock);
 591
 592		/* now walk dispose list and issue callbacks */
 593		list_for_each_safe(tmp, tmp2, &dispose_list) {
 594			mid_entry = list_entry(tmp, struct mid_q_entry, qhead);
 595			cFYI(1, "Callback mid 0x%x", mid_entry->mid);
 596			list_del_init(&mid_entry->qhead);
 597			mid_entry->callback(mid_entry);
 
 598		}
 599		/* 1/8th of sec is more than enough time for them to exit */
 600		msleep(125);
 601	}
 602
 603	if (!list_empty(&server->pending_mid_q)) {
 604		/*
 605		 * mpx threads have not exited yet give them at least the smb
 606		 * send timeout time for long ops.
 607		 *
 608		 * Due to delays on oplock break requests, we need to wait at
 609		 * least 45 seconds before giving up on a request getting a
 610		 * response and going ahead and killing cifsd.
 611		 */
 612		cFYI(1, "Wait for exit from demultiplex thread");
 613		msleep(46000);
 614		/*
 615		 * If threads still have not exited they are probably never
 616		 * coming home not much else we can do but free the memory.
 617		 */
 618	}
 619
 620	kfree(server->hostname);
 
 
 
 621	kfree(server);
 622
 623	length = atomic_dec_return(&tcpSesAllocCount);
 624	if (length > 0)
 625		mempool_resize(cifs_req_poolp, length + cifs_min_rcv,
 626				GFP_KERNEL);
 627}
 628
 629static int
 630cifs_demultiplex_thread(void *p)
 631{
 632	int length;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 633	struct TCP_Server_Info *server = p;
 634	unsigned int pdu_length, total_read;
 635	char *buf = NULL, *bigbuf = NULL, *smallbuf = NULL;
 636	struct smb_hdr *smb_buffer = NULL;
 637	struct msghdr smb_msg;
 638	struct kvec iov;
 639	struct task_struct *task_to_wake = NULL;
 640	struct mid_q_entry *mid_entry;
 641	bool isLargeBuf = false;
 642	bool isMultiRsp = false;
 643	int rc;
 644
 645	current->flags |= PF_MEMALLOC;
 646	cFYI(1, "Demultiplex PID: %d", task_pid_nr(current));
 647
 648	length = atomic_inc_return(&tcpSesAllocCount);
 649	if (length > 1)
 650		mempool_resize(cifs_req_poolp, length + cifs_min_rcv,
 651				GFP_KERNEL);
 652
 653	set_freezable();
 
 654	while (server->tcpStatus != CifsExiting) {
 655		if (try_to_freeze())
 656			continue;
 657
 658		if (!allocate_buffers(&bigbuf, &smallbuf,
 659				      sizeof(struct smb_hdr), isLargeBuf))
 660			continue;
 661
 662		isLargeBuf = false;
 663		isMultiRsp = false;
 664		smb_buffer = (struct smb_hdr *)smallbuf;
 665		buf = smallbuf;
 666		iov.iov_base = buf;
 667		iov.iov_len = 4;
 668		smb_msg.msg_control = NULL;
 669		smb_msg.msg_controllen = 0;
 670		pdu_length = 4; /* enough to get RFC1001 header */
 671
 672incomplete_rcv:
 673		if (echo_retries > 0 && server->tcpStatus == CifsGood &&
 674		    time_after(jiffies, server->lstrp +
 675					(echo_retries * SMB_ECHO_INTERVAL))) {
 676			cERROR(1, "Server %s has not responded in %d seconds. "
 677				  "Reconnecting...", server->hostname,
 678				  (echo_retries * SMB_ECHO_INTERVAL / HZ));
 679			cifs_reconnect(server);
 680			wake_up(&server->response_q);
 681			continue;
 682		}
 683
 684		rc = read_from_socket(server, &smb_msg, &iov, pdu_length,
 685				      &total_read, true /* header read */);
 686		if (rc == 3)
 687			goto incomplete_rcv;
 688		else if (rc == 2)
 689			break;
 690		else if (rc == 1)
 691			continue;
 692
 693		/*
 694		 * The right amount was read from socket - 4 bytes,
 695		 * so we can now interpret the length field.
 696		 */
 
 697
 698		/*
 699		 * Note that RFC 1001 length is big endian on the wire,
 700		 * but we convert it here so it is always manipulated
 701		 * as host byte order.
 702		 */
 703		pdu_length = be32_to_cpu(smb_buffer->smb_buf_length);
 704
 705		cFYI(1, "rfc1002 length 0x%x", pdu_length+4);
 706		if (!check_rfc1002_header(server, buf))
 707			continue;
 
 
 708
 709		/* else length ok */
 710		if (pdu_length > MAX_CIFS_SMALL_BUFFER_SIZE - 4) {
 711			isLargeBuf = true;
 712			memcpy(bigbuf, smallbuf, 4);
 713			smb_buffer = (struct smb_hdr *)bigbuf;
 714			buf = bigbuf;
 715		}
 716
 717		iov.iov_base = 4 + buf;
 718		iov.iov_len = pdu_length;
 719		rc = read_from_socket(server, &smb_msg, &iov, pdu_length,
 720				      &total_read, false);
 721		if (rc == 2)
 722			break;
 723		else if (rc == 1)
 724			continue;
 
 725
 726		total_read += 4; /* account for rfc1002 hdr */
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 727
 728		dump_smb(smb_buffer, total_read);
 
 
 
 
 729
 730		/*
 731		 * We know that we received enough to get to the MID as we
 732		 * checked the pdu_length earlier. Now check to see
 733		 * if the rest of the header is OK. We borrow the length
 734		 * var for the rest of the loop to avoid a new stack var.
 735		 *
 736		 * 48 bytes is enough to display the header and a little bit
 737		 * into the payload for debugging purposes.
 738		 */
 739		length = checkSMB(smb_buffer, smb_buffer->Mid, total_read);
 740		if (length != 0)
 741			cifs_dump_mem("Bad SMB: ", buf,
 742				      min_t(unsigned int, total_read, 48));
 
 
 
 743
 744		server->lstrp = jiffies;
 745
 746		mid_entry = find_cifs_mid(server, smb_buffer, &length,
 747					  isLargeBuf, &isMultiRsp, &bigbuf);
 748		if (mid_entry != NULL) {
 749			mid_entry->callback(mid_entry);
 750			/* Was previous buf put in mpx struct for multi-rsp? */
 751			if (!isMultiRsp) {
 752				/* smb buffer will be freed by user thread */
 753				if (isLargeBuf)
 754					bigbuf = NULL;
 755				else
 756					smallbuf = NULL;
 757			}
 758		} else if (length != 0) {
 759			/* response sanity checks failed */
 760			continue;
 761		} else if (!is_valid_oplock_break(smb_buffer, server) &&
 762			   !isMultiRsp) {
 763			cERROR(1, "No task to wake, unknown frame received! "
 764				   "NumMids %d", atomic_read(&midCount));
 765			cifs_dump_mem("Received Data is: ", buf,
 766				      sizeof(struct smb_hdr));
 
 
 767#ifdef CONFIG_CIFS_DEBUG2
 768			cifs_dump_detail(smb_buffer);
 769			cifs_dump_mids(server);
 
 
 770#endif /* CIFS_DEBUG2 */
 
 
 771
 
 
 
 
 
 
 
 
 772		}
 773	} /* end while !EXITING */
 774
 775	/* buffer usually freed in free_mid - need to free it here on exit */
 776	cifs_buf_release(bigbuf);
 777	if (smallbuf) /* no sense logging a debug message if NULL */
 778		cifs_small_buf_release(smallbuf);
 779
 780	task_to_wake = xchg(&server->tsk, NULL);
 781	clean_demultiplex_info(server);
 782
 783	/* if server->tsk was NULL then wait for a signal before exiting */
 784	if (!task_to_wake) {
 785		set_current_state(TASK_INTERRUPTIBLE);
 786		while (!signal_pending(current)) {
 787			schedule();
 788			set_current_state(TASK_INTERRUPTIBLE);
 789		}
 790		set_current_state(TASK_RUNNING);
 791	}
 792
 793	module_put_and_exit(0);
 
 794}
 795
 796/* extract the host portion of the UNC string */
 797static char *
 798extract_hostname(const char *unc)
 799{
 800	const char *src;
 801	char *dst, *delim;
 802	unsigned int len;
 803
 804	/* skip double chars at beginning of string */
 805	/* BB: check validity of these bytes? */
 806	src = unc + 2;
 807
 808	/* delimiter between hostname and sharename is always '\\' now */
 809	delim = strchr(src, '\\');
 810	if (!delim)
 811		return ERR_PTR(-EINVAL);
 812
 813	len = delim - src;
 814	dst = kmalloc((len + 1), GFP_KERNEL);
 815	if (dst == NULL)
 816		return ERR_PTR(-ENOMEM);
 817
 818	memcpy(dst, src, len);
 819	dst[len] = '\0';
 820
 821	return dst;
 822}
 823
 824static int
 825cifs_parse_mount_options(const char *mountdata, const char *devname,
 826			 struct smb_vol *vol)
 827{
 828	char *value, *data, *end;
 829	char *mountdata_copy = NULL, *options;
 830	unsigned int  temp_len, i, j;
 831	char separator[2];
 832	short int override_uid = -1;
 833	short int override_gid = -1;
 834	bool uid_specified = false;
 835	bool gid_specified = false;
 836	char *nodename = utsname()->nodename;
 837
 838	separator[0] = ',';
 839	separator[1] = 0;
 840
 841	/*
 842	 * does not have to be perfect mapping since field is
 843	 * informational, only used for servers that do not support
 844	 * port 445 and it can be overridden at mount time
 845	 */
 846	memset(vol->source_rfc1001_name, 0x20, RFC1001_NAME_LEN);
 847	for (i = 0; i < strnlen(nodename, RFC1001_NAME_LEN); i++)
 848		vol->source_rfc1001_name[i] = toupper(nodename[i]);
 849
 850	vol->source_rfc1001_name[RFC1001_NAME_LEN] = 0;
 851	/* null target name indicates to use *SMBSERVR default called name
 852	   if we end up sending RFC1001 session initialize */
 853	vol->target_rfc1001_name[0] = 0;
 854	vol->cred_uid = current_uid();
 855	vol->linux_uid = current_uid();
 856	vol->linux_gid = current_gid();
 857
 858	/* default to only allowing write access to owner of the mount */
 859	vol->dir_mode = vol->file_mode = S_IRUGO | S_IXUGO | S_IWUSR;
 860
 861	/* vol->retry default is 0 (i.e. "soft" limited retry not hard retry) */
 862	/* default is always to request posix paths. */
 863	vol->posix_paths = 1;
 864	/* default to using server inode numbers where available */
 865	vol->server_ino = 1;
 866
 867	vol->actimeo = CIFS_DEF_ACTIMEO;
 868
 869	if (!mountdata)
 870		goto cifs_parse_mount_err;
 871
 872	mountdata_copy = kstrndup(mountdata, PAGE_SIZE, GFP_KERNEL);
 873	if (!mountdata_copy)
 874		goto cifs_parse_mount_err;
 875
 876	options = mountdata_copy;
 877	end = options + strlen(options);
 878	if (strncmp(options, "sep=", 4) == 0) {
 879		if (options[4] != 0) {
 880			separator[0] = options[4];
 881			options += 5;
 882		} else {
 883			cFYI(1, "Null separator not allowed");
 884		}
 885	}
 886
 887	while ((data = strsep(&options, separator)) != NULL) {
 888		if (!*data)
 889			continue;
 890		if ((value = strchr(data, '=')) != NULL)
 891			*value++ = '\0';
 892
 893		/* Have to parse this before we parse for "user" */
 894		if (strnicmp(data, "user_xattr", 10) == 0) {
 895			vol->no_xattr = 0;
 896		} else if (strnicmp(data, "nouser_xattr", 12) == 0) {
 897			vol->no_xattr = 1;
 898		} else if (strnicmp(data, "user", 4) == 0) {
 899			if (!value) {
 900				printk(KERN_WARNING
 901				       "CIFS: invalid or missing username\n");
 902				goto cifs_parse_mount_err;
 903			} else if (!*value) {
 904				/* null user, ie anonymous, authentication */
 905				vol->nullauth = 1;
 906			}
 907			if (strnlen(value, MAX_USERNAME_SIZE) <
 908						MAX_USERNAME_SIZE) {
 909				vol->username = kstrdup(value, GFP_KERNEL);
 910				if (!vol->username) {
 911					printk(KERN_WARNING "CIFS: no memory "
 912							    "for username\n");
 913					goto cifs_parse_mount_err;
 914				}
 915			} else {
 916				printk(KERN_WARNING "CIFS: username too long\n");
 917				goto cifs_parse_mount_err;
 918			}
 919		} else if (strnicmp(data, "pass", 4) == 0) {
 920			if (!value) {
 921				vol->password = NULL;
 922				continue;
 923			} else if (value[0] == 0) {
 924				/* check if string begins with double comma
 925				   since that would mean the password really
 926				   does start with a comma, and would not
 927				   indicate an empty string */
 928				if (value[1] != separator[0]) {
 929					vol->password = NULL;
 930					continue;
 931				}
 932			}
 933			temp_len = strlen(value);
 934			/* removed password length check, NTLM passwords
 935				can be arbitrarily long */
 936
 937			/* if comma in password, the string will be
 938			prematurely null terminated.  Commas in password are
 939			specified across the cifs mount interface by a double
 940			comma ie ,, and a comma used as in other cases ie ','
 941			as a parameter delimiter/separator is single and due
 942			to the strsep above is temporarily zeroed. */
 943
 944			/* NB: password legally can have multiple commas and
 945			the only illegal character in a password is null */
 946
 947			if ((value[temp_len] == 0) &&
 948			    (value + temp_len < end) &&
 949			    (value[temp_len+1] == separator[0])) {
 950				/* reinsert comma */
 951				value[temp_len] = separator[0];
 952				temp_len += 2;  /* move after second comma */
 953				while (value[temp_len] != 0)  {
 954					if (value[temp_len] == separator[0]) {
 955						if (value[temp_len+1] ==
 956						     separator[0]) {
 957						/* skip second comma */
 958							temp_len++;
 959						} else {
 960						/* single comma indicating start
 961							 of next parm */
 962							break;
 963						}
 964					}
 965					temp_len++;
 966				}
 967				if (value[temp_len] == 0) {
 968					options = NULL;
 969				} else {
 970					value[temp_len] = 0;
 971					/* point option to start of next parm */
 972					options = value + temp_len + 1;
 973				}
 974				/* go from value to value + temp_len condensing
 975				double commas to singles. Note that this ends up
 976				allocating a few bytes too many, which is ok */
 977				vol->password = kzalloc(temp_len, GFP_KERNEL);
 978				if (vol->password == NULL) {
 979					printk(KERN_WARNING "CIFS: no memory "
 980							    "for password\n");
 981					goto cifs_parse_mount_err;
 982				}
 983				for (i = 0, j = 0; i < temp_len; i++, j++) {
 984					vol->password[j] = value[i];
 985					if (value[i] == separator[0]
 986						&& value[i+1] == separator[0]) {
 987						/* skip second comma */
 988						i++;
 989					}
 990				}
 991				vol->password[j] = 0;
 992			} else {
 993				vol->password = kzalloc(temp_len+1, GFP_KERNEL);
 994				if (vol->password == NULL) {
 995					printk(KERN_WARNING "CIFS: no memory "
 996							    "for password\n");
 997					goto cifs_parse_mount_err;
 998				}
 999				strcpy(vol->password, value);
1000			}
1001		} else if (!strnicmp(data, "ip", 2) ||
1002			   !strnicmp(data, "addr", 4)) {
1003			if (!value || !*value) {
1004				vol->UNCip = NULL;
1005			} else if (strnlen(value, INET6_ADDRSTRLEN) <
1006							INET6_ADDRSTRLEN) {
1007				vol->UNCip = kstrdup(value, GFP_KERNEL);
1008				if (!vol->UNCip) {
1009					printk(KERN_WARNING "CIFS: no memory "
1010							    "for UNC IP\n");
1011					goto cifs_parse_mount_err;
1012				}
1013			} else {
1014				printk(KERN_WARNING "CIFS: ip address "
1015						    "too long\n");
1016				goto cifs_parse_mount_err;
1017			}
1018		} else if (strnicmp(data, "sec", 3) == 0) {
1019			if (!value || !*value) {
1020				cERROR(1, "no security value specified");
1021				continue;
1022			} else if (strnicmp(value, "krb5i", 5) == 0) {
1023				vol->secFlg |= CIFSSEC_MAY_KRB5 |
1024					CIFSSEC_MUST_SIGN;
1025			} else if (strnicmp(value, "krb5p", 5) == 0) {
1026				/* vol->secFlg |= CIFSSEC_MUST_SEAL |
1027					CIFSSEC_MAY_KRB5; */
1028				cERROR(1, "Krb5 cifs privacy not supported");
1029				goto cifs_parse_mount_err;
1030			} else if (strnicmp(value, "krb5", 4) == 0) {
1031				vol->secFlg |= CIFSSEC_MAY_KRB5;
1032			} else if (strnicmp(value, "ntlmsspi", 8) == 0) {
1033				vol->secFlg |= CIFSSEC_MAY_NTLMSSP |
1034					CIFSSEC_MUST_SIGN;
1035			} else if (strnicmp(value, "ntlmssp", 7) == 0) {
1036				vol->secFlg |= CIFSSEC_MAY_NTLMSSP;
1037			} else if (strnicmp(value, "ntlmv2i", 7) == 0) {
1038				vol->secFlg |= CIFSSEC_MAY_NTLMV2 |
1039					CIFSSEC_MUST_SIGN;
1040			} else if (strnicmp(value, "ntlmv2", 6) == 0) {
1041				vol->secFlg |= CIFSSEC_MAY_NTLMV2;
1042			} else if (strnicmp(value, "ntlmi", 5) == 0) {
1043				vol->secFlg |= CIFSSEC_MAY_NTLM |
1044					CIFSSEC_MUST_SIGN;
1045			} else if (strnicmp(value, "ntlm", 4) == 0) {
1046				/* ntlm is default so can be turned off too */
1047				vol->secFlg |= CIFSSEC_MAY_NTLM;
1048			} else if (strnicmp(value, "nontlm", 6) == 0) {
1049				/* BB is there a better way to do this? */
1050				vol->secFlg |= CIFSSEC_MAY_NTLMV2;
1051#ifdef CONFIG_CIFS_WEAK_PW_HASH
1052			} else if (strnicmp(value, "lanman", 6) == 0) {
1053				vol->secFlg |= CIFSSEC_MAY_LANMAN;
1054#endif
1055			} else if (strnicmp(value, "none", 4) == 0) {
1056				vol->nullauth = 1;
1057			} else {
1058				cERROR(1, "bad security option: %s", value);
1059				goto cifs_parse_mount_err;
1060			}
1061		} else if (strnicmp(data, "vers", 3) == 0) {
1062			if (!value || !*value) {
1063				cERROR(1, "no protocol version specified"
1064					  " after vers= mount option");
1065			} else if ((strnicmp(value, "cifs", 4) == 0) ||
1066				   (strnicmp(value, "1", 1) == 0)) {
1067				/* this is the default */
1068				continue;
1069			}
1070		} else if ((strnicmp(data, "unc", 3) == 0)
1071			   || (strnicmp(data, "target", 6) == 0)
1072			   || (strnicmp(data, "path", 4) == 0)) {
1073			if (!value || !*value) {
1074				printk(KERN_WARNING "CIFS: invalid path to "
1075						    "network resource\n");
1076				goto cifs_parse_mount_err;
1077			}
1078			if ((temp_len = strnlen(value, 300)) < 300) {
1079				vol->UNC = kmalloc(temp_len+1, GFP_KERNEL);
1080				if (vol->UNC == NULL)
1081					goto cifs_parse_mount_err;
1082				strcpy(vol->UNC, value);
1083				if (strncmp(vol->UNC, "//", 2) == 0) {
1084					vol->UNC[0] = '\\';
1085					vol->UNC[1] = '\\';
1086				} else if (strncmp(vol->UNC, "\\\\", 2) != 0) {
1087					printk(KERN_WARNING
1088					       "CIFS: UNC Path does not begin "
1089					       "with // or \\\\ \n");
1090					goto cifs_parse_mount_err;
1091				}
1092			} else {
1093				printk(KERN_WARNING "CIFS: UNC name too long\n");
1094				goto cifs_parse_mount_err;
1095			}
1096		} else if ((strnicmp(data, "domain", 3) == 0)
1097			   || (strnicmp(data, "workgroup", 5) == 0)) {
1098			if (!value || !*value) {
1099				printk(KERN_WARNING "CIFS: invalid domain name\n");
1100				goto cifs_parse_mount_err;
1101			}
1102			/* BB are there cases in which a comma can be valid in
1103			a domain name and need special handling? */
1104			if (strnlen(value, 256) < 256) {
1105				vol->domainname = kstrdup(value, GFP_KERNEL);
1106				if (!vol->domainname) {
1107					printk(KERN_WARNING "CIFS: no memory "
1108							    "for domainname\n");
1109					goto cifs_parse_mount_err;
1110				}
1111				cFYI(1, "Domain name set");
1112			} else {
1113				printk(KERN_WARNING "CIFS: domain name too "
1114						    "long\n");
1115				goto cifs_parse_mount_err;
1116			}
1117		} else if (strnicmp(data, "srcaddr", 7) == 0) {
1118			vol->srcaddr.ss_family = AF_UNSPEC;
1119
1120			if (!value || !*value) {
1121				printk(KERN_WARNING "CIFS: srcaddr value"
1122				       " not specified.\n");
1123				goto cifs_parse_mount_err;
1124			}
1125			i = cifs_convert_address((struct sockaddr *)&vol->srcaddr,
1126						 value, strlen(value));
1127			if (i == 0) {
1128				printk(KERN_WARNING "CIFS:  Could not parse"
1129				       " srcaddr: %s\n",
1130				       value);
1131				goto cifs_parse_mount_err;
1132			}
1133		} else if (strnicmp(data, "prefixpath", 10) == 0) {
1134			if (!value || !*value) {
1135				printk(KERN_WARNING
1136					"CIFS: invalid path prefix\n");
1137				goto cifs_parse_mount_err;
1138			}
1139			if ((temp_len = strnlen(value, 1024)) < 1024) {
1140				if (value[0] != '/')
1141					temp_len++;  /* missing leading slash */
1142				vol->prepath = kmalloc(temp_len+1, GFP_KERNEL);
1143				if (vol->prepath == NULL)
1144					goto cifs_parse_mount_err;
1145				if (value[0] != '/') {
1146					vol->prepath[0] = '/';
1147					strcpy(vol->prepath+1, value);
1148				} else
1149					strcpy(vol->prepath, value);
1150				cFYI(1, "prefix path %s", vol->prepath);
1151			} else {
1152				printk(KERN_WARNING "CIFS: prefix too long\n");
1153				goto cifs_parse_mount_err;
1154			}
1155		} else if (strnicmp(data, "iocharset", 9) == 0) {
1156			if (!value || !*value) {
1157				printk(KERN_WARNING "CIFS: invalid iocharset "
1158						    "specified\n");
1159				goto cifs_parse_mount_err;
1160			}
1161			if (strnlen(value, 65) < 65) {
1162				if (strnicmp(value, "default", 7)) {
1163					vol->iocharset = kstrdup(value,
1164								 GFP_KERNEL);
1165
1166					if (!vol->iocharset) {
1167						printk(KERN_WARNING "CIFS: no "
1168								   "memory for"
1169								   "charset\n");
1170						goto cifs_parse_mount_err;
1171					}
1172				}
1173				/* if iocharset not set then load_nls_default
1174				   is used by caller */
1175				cFYI(1, "iocharset set to %s", value);
1176			} else {
1177				printk(KERN_WARNING "CIFS: iocharset name "
1178						    "too long.\n");
1179				goto cifs_parse_mount_err;
1180			}
1181		} else if (!strnicmp(data, "uid", 3) && value && *value) {
1182			vol->linux_uid = simple_strtoul(value, &value, 0);
1183			uid_specified = true;
1184		} else if (!strnicmp(data, "cruid", 5) && value && *value) {
1185			vol->cred_uid = simple_strtoul(value, &value, 0);
1186		} else if (!strnicmp(data, "forceuid", 8)) {
1187			override_uid = 1;
1188		} else if (!strnicmp(data, "noforceuid", 10)) {
1189			override_uid = 0;
1190		} else if (!strnicmp(data, "gid", 3) && value && *value) {
1191			vol->linux_gid = simple_strtoul(value, &value, 0);
1192			gid_specified = true;
1193		} else if (!strnicmp(data, "forcegid", 8)) {
1194			override_gid = 1;
1195		} else if (!strnicmp(data, "noforcegid", 10)) {
1196			override_gid = 0;
1197		} else if (strnicmp(data, "file_mode", 4) == 0) {
1198			if (value && *value) {
1199				vol->file_mode =
1200					simple_strtoul(value, &value, 0);
1201			}
1202		} else if (strnicmp(data, "dir_mode", 4) == 0) {
1203			if (value && *value) {
1204				vol->dir_mode =
1205					simple_strtoul(value, &value, 0);
1206			}
1207		} else if (strnicmp(data, "dirmode", 4) == 0) {
1208			if (value && *value) {
1209				vol->dir_mode =
1210					simple_strtoul(value, &value, 0);
1211			}
1212		} else if (strnicmp(data, "port", 4) == 0) {
1213			if (value && *value) {
1214				vol->port =
1215					simple_strtoul(value, &value, 0);
1216			}
1217		} else if (strnicmp(data, "rsize", 5) == 0) {
1218			if (value && *value) {
1219				vol->rsize =
1220					simple_strtoul(value, &value, 0);
1221			}
1222		} else if (strnicmp(data, "wsize", 5) == 0) {
1223			if (value && *value) {
1224				vol->wsize =
1225					simple_strtoul(value, &value, 0);
1226			}
1227		} else if (strnicmp(data, "sockopt", 5) == 0) {
1228			if (!value || !*value) {
1229				cERROR(1, "no socket option specified");
1230				continue;
1231			} else if (strnicmp(value, "TCP_NODELAY", 11) == 0) {
1232				vol->sockopt_tcp_nodelay = 1;
1233			}
1234		} else if (strnicmp(data, "netbiosname", 4) == 0) {
1235			if (!value || !*value || (*value == ' ')) {
1236				cFYI(1, "invalid (empty) netbiosname");
1237			} else {
1238				memset(vol->source_rfc1001_name, 0x20,
1239					RFC1001_NAME_LEN);
1240				/*
1241				 * FIXME: are there cases in which a comma can
1242				 * be valid in workstation netbios name (and
1243				 * need special handling)?
1244				 */
1245				for (i = 0; i < RFC1001_NAME_LEN; i++) {
1246					/* don't ucase netbiosname for user */
1247					if (value[i] == 0)
1248						break;
1249					vol->source_rfc1001_name[i] = value[i];
1250				}
1251				/* The string has 16th byte zero still from
1252				set at top of the function  */
1253				if (i == RFC1001_NAME_LEN && value[i] != 0)
1254					printk(KERN_WARNING "CIFS: netbiosname"
1255						" longer than 15 truncated.\n");
1256			}
1257		} else if (strnicmp(data, "servern", 7) == 0) {
1258			/* servernetbiosname specified override *SMBSERVER */
1259			if (!value || !*value || (*value == ' ')) {
1260				cFYI(1, "empty server netbiosname specified");
1261			} else {
1262				/* last byte, type, is 0x20 for servr type */
1263				memset(vol->target_rfc1001_name, 0x20,
1264					RFC1001_NAME_LEN_WITH_NULL);
1265
1266				for (i = 0; i < 15; i++) {
1267				/* BB are there cases in which a comma can be
1268				   valid in this workstation netbios name
1269				   (and need special handling)? */
1270
1271				/* user or mount helper must uppercase
1272				   the netbiosname */
1273					if (value[i] == 0)
1274						break;
1275					else
1276						vol->target_rfc1001_name[i] =
1277								value[i];
1278				}
1279				/* The string has 16th byte zero still from
1280				   set at top of the function  */
1281				if (i == RFC1001_NAME_LEN && value[i] != 0)
1282					printk(KERN_WARNING "CIFS: server net"
1283					"biosname longer than 15 truncated.\n");
1284			}
1285		} else if (strnicmp(data, "actimeo", 7) == 0) {
1286			if (value && *value) {
1287				vol->actimeo = HZ * simple_strtoul(value,
1288								   &value, 0);
1289				if (vol->actimeo > CIFS_MAX_ACTIMEO) {
1290					cERROR(1, "CIFS: attribute cache"
1291							"timeout too large");
1292					goto cifs_parse_mount_err;
1293				}
1294			}
1295		} else if (strnicmp(data, "credentials", 4) == 0) {
1296			/* ignore */
1297		} else if (strnicmp(data, "version", 3) == 0) {
1298			/* ignore */
1299		} else if (strnicmp(data, "guest", 5) == 0) {
1300			/* ignore */
1301		} else if (strnicmp(data, "rw", 2) == 0 && strlen(data) == 2) {
1302			/* ignore */
1303		} else if (strnicmp(data, "ro", 2) == 0) {
1304			/* ignore */
1305		} else if (strnicmp(data, "noblocksend", 11) == 0) {
1306			vol->noblocksnd = 1;
1307		} else if (strnicmp(data, "noautotune", 10) == 0) {
1308			vol->noautotune = 1;
1309		} else if ((strnicmp(data, "suid", 4) == 0) ||
1310				   (strnicmp(data, "nosuid", 6) == 0) ||
1311				   (strnicmp(data, "exec", 4) == 0) ||
1312				   (strnicmp(data, "noexec", 6) == 0) ||
1313				   (strnicmp(data, "nodev", 5) == 0) ||
1314				   (strnicmp(data, "noauto", 6) == 0) ||
1315				   (strnicmp(data, "dev", 3) == 0)) {
1316			/*  The mount tool or mount.cifs helper (if present)
1317			    uses these opts to set flags, and the flags are read
1318			    by the kernel vfs layer before we get here (ie
1319			    before read super) so there is no point trying to
1320			    parse these options again and set anything and it
1321			    is ok to just ignore them */
1322			continue;
1323		} else if (strnicmp(data, "hard", 4) == 0) {
1324			vol->retry = 1;
1325		} else if (strnicmp(data, "soft", 4) == 0) {
1326			vol->retry = 0;
1327		} else if (strnicmp(data, "perm", 4) == 0) {
1328			vol->noperm = 0;
1329		} else if (strnicmp(data, "noperm", 6) == 0) {
1330			vol->noperm = 1;
1331		} else if (strnicmp(data, "mapchars", 8) == 0) {
1332			vol->remap = 1;
1333		} else if (strnicmp(data, "nomapchars", 10) == 0) {
1334			vol->remap = 0;
1335		} else if (strnicmp(data, "sfu", 3) == 0) {
1336			vol->sfu_emul = 1;
1337		} else if (strnicmp(data, "nosfu", 5) == 0) {
1338			vol->sfu_emul = 0;
1339		} else if (strnicmp(data, "nodfs", 5) == 0) {
1340			vol->nodfs = 1;
1341		} else if (strnicmp(data, "posixpaths", 10) == 0) {
1342			vol->posix_paths = 1;
1343		} else if (strnicmp(data, "noposixpaths", 12) == 0) {
1344			vol->posix_paths = 0;
1345		} else if (strnicmp(data, "nounix", 6) == 0) {
1346			vol->no_linux_ext = 1;
1347		} else if (strnicmp(data, "nolinux", 7) == 0) {
1348			vol->no_linux_ext = 1;
1349		} else if ((strnicmp(data, "nocase", 6) == 0) ||
1350			   (strnicmp(data, "ignorecase", 10)  == 0)) {
1351			vol->nocase = 1;
1352		} else if (strnicmp(data, "mand", 4) == 0) {
1353			/* ignore */
1354		} else if (strnicmp(data, "nomand", 6) == 0) {
1355			/* ignore */
1356		} else if (strnicmp(data, "_netdev", 7) == 0) {
1357			/* ignore */
1358		} else if (strnicmp(data, "brl", 3) == 0) {
1359			vol->nobrl =  0;
1360		} else if ((strnicmp(data, "nobrl", 5) == 0) ||
1361			   (strnicmp(data, "nolock", 6) == 0)) {
1362			vol->nobrl =  1;
1363			/* turn off mandatory locking in mode
1364			if remote locking is turned off since the
1365			local vfs will do advisory */
1366			if (vol->file_mode ==
1367				(S_IALLUGO & ~(S_ISUID | S_IXGRP)))
1368				vol->file_mode = S_IALLUGO;
1369		} else if (strnicmp(data, "forcemandatorylock", 9) == 0) {
1370			/* will take the shorter form "forcemand" as well */
1371			/* This mount option will force use of mandatory
1372			  (DOS/Windows style) byte range locks, instead of
1373			  using posix advisory byte range locks, even if the
1374			  Unix extensions are available and posix locks would
1375			  be supported otherwise. If Unix extensions are not
1376			  negotiated this has no effect since mandatory locks
1377			  would be used (mandatory locks is all that those
1378			  those servers support) */
1379			vol->mand_lock = 1;
1380		} else if (strnicmp(data, "setuids", 7) == 0) {
1381			vol->setuids = 1;
1382		} else if (strnicmp(data, "nosetuids", 9) == 0) {
1383			vol->setuids = 0;
1384		} else if (strnicmp(data, "dynperm", 7) == 0) {
1385			vol->dynperm = true;
1386		} else if (strnicmp(data, "nodynperm", 9) == 0) {
1387			vol->dynperm = false;
1388		} else if (strnicmp(data, "nohard", 6) == 0) {
1389			vol->retry = 0;
1390		} else if (strnicmp(data, "nosoft", 6) == 0) {
1391			vol->retry = 1;
1392		} else if (strnicmp(data, "nointr", 6) == 0) {
1393			vol->intr = 0;
1394		} else if (strnicmp(data, "intr", 4) == 0) {
1395			vol->intr = 1;
1396		} else if (strnicmp(data, "nostrictsync", 12) == 0) {
1397			vol->nostrictsync = 1;
1398		} else if (strnicmp(data, "strictsync", 10) == 0) {
1399			vol->nostrictsync = 0;
1400		} else if (strnicmp(data, "serverino", 7) == 0) {
1401			vol->server_ino = 1;
1402		} else if (strnicmp(data, "noserverino", 9) == 0) {
1403			vol->server_ino = 0;
1404		} else if (strnicmp(data, "rwpidforward", 12) == 0) {
1405			vol->rwpidforward = 1;
1406		} else if (strnicmp(data, "cifsacl", 7) == 0) {
1407			vol->cifs_acl = 1;
1408		} else if (strnicmp(data, "nocifsacl", 9) == 0) {
1409			vol->cifs_acl = 0;
1410		} else if (strnicmp(data, "acl", 3) == 0) {
1411			vol->no_psx_acl = 0;
1412		} else if (strnicmp(data, "noacl", 5) == 0) {
1413			vol->no_psx_acl = 1;
1414		} else if (strnicmp(data, "locallease", 6) == 0) {
1415			vol->local_lease = 1;
1416		} else if (strnicmp(data, "sign", 4) == 0) {
1417			vol->secFlg |= CIFSSEC_MUST_SIGN;
1418		} else if (strnicmp(data, "seal", 4) == 0) {
1419			/* we do not do the following in secFlags because seal
1420			   is a per tree connection (mount) not a per socket
1421			   or per-smb connection option in the protocol */
1422			/* vol->secFlg |= CIFSSEC_MUST_SEAL; */
1423			vol->seal = 1;
1424		} else if (strnicmp(data, "direct", 6) == 0) {
1425			vol->direct_io = 1;
1426		} else if (strnicmp(data, "forcedirectio", 13) == 0) {
1427			vol->direct_io = 1;
1428		} else if (strnicmp(data, "strictcache", 11) == 0) {
1429			vol->strict_io = 1;
1430		} else if (strnicmp(data, "noac", 4) == 0) {
1431			printk(KERN_WARNING "CIFS: Mount option noac not "
1432				"supported. Instead set "
1433				"/proc/fs/cifs/LookupCacheEnabled to 0\n");
1434		} else if (strnicmp(data, "fsc", 3) == 0) {
1435#ifndef CONFIG_CIFS_FSCACHE
1436			cERROR(1, "FS-Cache support needs CONFIG_CIFS_FSCACHE "
1437				  "kernel config option set");
1438			goto cifs_parse_mount_err;
1439#endif
1440			vol->fsc = true;
1441		} else if (strnicmp(data, "mfsymlinks", 10) == 0) {
1442			vol->mfsymlinks = true;
1443		} else if (strnicmp(data, "multiuser", 8) == 0) {
1444			vol->multiuser = true;
1445		} else
1446			printk(KERN_WARNING "CIFS: Unknown mount option %s\n",
1447						data);
1448	}
1449	if (vol->UNC == NULL) {
1450		if (devname == NULL) {
1451			printk(KERN_WARNING "CIFS: Missing UNC name for mount "
1452						"target\n");
1453			goto cifs_parse_mount_err;
1454		}
1455		if ((temp_len = strnlen(devname, 300)) < 300) {
1456			vol->UNC = kmalloc(temp_len+1, GFP_KERNEL);
1457			if (vol->UNC == NULL)
1458				goto cifs_parse_mount_err;
1459			strcpy(vol->UNC, devname);
1460			if (strncmp(vol->UNC, "//", 2) == 0) {
1461				vol->UNC[0] = '\\';
1462				vol->UNC[1] = '\\';
1463			} else if (strncmp(vol->UNC, "\\\\", 2) != 0) {
1464				printk(KERN_WARNING "CIFS: UNC Path does not "
1465						    "begin with // or \\\\ \n");
1466				goto cifs_parse_mount_err;
1467			}
1468			value = strpbrk(vol->UNC+2, "/\\");
1469			if (value)
1470				*value = '\\';
1471		} else {
1472			printk(KERN_WARNING "CIFS: UNC name too long\n");
1473			goto cifs_parse_mount_err;
1474		}
1475	}
1476
1477	if (vol->multiuser && !(vol->secFlg & CIFSSEC_MAY_KRB5)) {
1478		cERROR(1, "Multiuser mounts currently require krb5 "
1479			  "authentication!");
1480		goto cifs_parse_mount_err;
1481	}
1482
1483	if (vol->UNCip == NULL)
1484		vol->UNCip = &vol->UNC[2];
1485
1486	if (uid_specified)
1487		vol->override_uid = override_uid;
1488	else if (override_uid == 1)
1489		printk(KERN_NOTICE "CIFS: ignoring forceuid mount option "
1490				   "specified with no uid= option.\n");
1491
1492	if (gid_specified)
1493		vol->override_gid = override_gid;
1494	else if (override_gid == 1)
1495		printk(KERN_NOTICE "CIFS: ignoring forcegid mount option "
1496				   "specified with no gid= option.\n");
1497
1498	kfree(mountdata_copy);
1499	return 0;
1500
1501cifs_parse_mount_err:
1502	kfree(mountdata_copy);
1503	return 1;
1504}
1505
1506/** Returns true if srcaddr isn't specified and rhs isn't
1507 * specified, or if srcaddr is specified and
1508 * matches the IP address of the rhs argument.
1509 */
1510static bool
1511srcip_matches(struct sockaddr *srcaddr, struct sockaddr *rhs)
1512{
1513	switch (srcaddr->sa_family) {
1514	case AF_UNSPEC:
1515		return (rhs->sa_family == AF_UNSPEC);
1516	case AF_INET: {
1517		struct sockaddr_in *saddr4 = (struct sockaddr_in *)srcaddr;
1518		struct sockaddr_in *vaddr4 = (struct sockaddr_in *)rhs;
1519		return (saddr4->sin_addr.s_addr == vaddr4->sin_addr.s_addr);
1520	}
1521	case AF_INET6: {
1522		struct sockaddr_in6 *saddr6 = (struct sockaddr_in6 *)srcaddr;
1523		struct sockaddr_in6 *vaddr6 = (struct sockaddr_in6 *)&rhs;
1524		return ipv6_addr_equal(&saddr6->sin6_addr, &vaddr6->sin6_addr);
1525	}
1526	default:
1527		WARN_ON(1);
1528		return false; /* don't expect to be here */
1529	}
1530}
1531
1532/*
1533 * If no port is specified in addr structure, we try to match with 445 port
1534 * and if it fails - with 139 ports. It should be called only if address
1535 * families of server and addr are equal.
1536 */
1537static bool
1538match_port(struct TCP_Server_Info *server, struct sockaddr *addr)
1539{
1540	__be16 port, *sport;
1541
 
 
 
 
1542	switch (addr->sa_family) {
1543	case AF_INET:
1544		sport = &((struct sockaddr_in *) &server->dstaddr)->sin_port;
1545		port = ((struct sockaddr_in *) addr)->sin_port;
1546		break;
1547	case AF_INET6:
1548		sport = &((struct sockaddr_in6 *) &server->dstaddr)->sin6_port;
1549		port = ((struct sockaddr_in6 *) addr)->sin6_port;
1550		break;
1551	default:
1552		WARN_ON(1);
1553		return false;
1554	}
1555
1556	if (!port) {
1557		port = htons(CIFS_PORT);
1558		if (port == *sport)
1559			return true;
1560
1561		port = htons(RFC1001_PORT);
1562	}
1563
1564	return port == *sport;
1565}
1566
1567static bool
1568match_address(struct TCP_Server_Info *server, struct sockaddr *addr,
1569	      struct sockaddr *srcaddr)
1570{
1571	switch (addr->sa_family) {
1572	case AF_INET: {
1573		struct sockaddr_in *addr4 = (struct sockaddr_in *)addr;
1574		struct sockaddr_in *srv_addr4 =
1575					(struct sockaddr_in *)&server->dstaddr;
1576
1577		if (addr4->sin_addr.s_addr != srv_addr4->sin_addr.s_addr)
1578			return false;
1579		break;
1580	}
1581	case AF_INET6: {
1582		struct sockaddr_in6 *addr6 = (struct sockaddr_in6 *)addr;
1583		struct sockaddr_in6 *srv_addr6 =
1584					(struct sockaddr_in6 *)&server->dstaddr;
1585
1586		if (!ipv6_addr_equal(&addr6->sin6_addr,
1587				     &srv_addr6->sin6_addr))
1588			return false;
1589		if (addr6->sin6_scope_id != srv_addr6->sin6_scope_id)
1590			return false;
1591		break;
1592	}
1593	default:
1594		WARN_ON(1);
1595		return false; /* don't expect to be here */
1596	}
1597
1598	if (!srcip_matches(srcaddr, (struct sockaddr *)&server->srcaddr))
1599		return false;
1600
1601	return true;
1602}
1603
1604static bool
1605match_security(struct TCP_Server_Info *server, struct smb_vol *vol)
1606{
1607	unsigned int secFlags;
1608
1609	if (vol->secFlg & (~(CIFSSEC_MUST_SIGN | CIFSSEC_MUST_SEAL)))
1610		secFlags = vol->secFlg;
1611	else
1612		secFlags = global_secflags | vol->secFlg;
 
 
1613
1614	switch (server->secType) {
1615	case LANMAN:
1616		if (!(secFlags & (CIFSSEC_MAY_LANMAN|CIFSSEC_MAY_PLNTXT)))
1617			return false;
1618		break;
1619	case NTLMv2:
1620		if (!(secFlags & CIFSSEC_MAY_NTLMV2))
1621			return false;
1622		break;
1623	case NTLM:
1624		if (!(secFlags & CIFSSEC_MAY_NTLM))
1625			return false;
1626		break;
1627	case Kerberos:
1628		if (!(secFlags & CIFSSEC_MAY_KRB5))
1629			return false;
1630		break;
1631	case RawNTLMSSP:
1632		if (!(secFlags & CIFSSEC_MAY_NTLMSSP))
1633			return false;
1634		break;
1635	default:
1636		/* shouldn't happen */
1637		return false;
1638	}
1639
1640	/* now check if signing mode is acceptable */
1641	if ((secFlags & CIFSSEC_MAY_SIGN) == 0 &&
1642	    (server->sec_mode & SECMODE_SIGN_REQUIRED))
1643			return false;
1644	else if (((secFlags & CIFSSEC_MUST_SIGN) == CIFSSEC_MUST_SIGN) &&
1645		 (server->sec_mode &
1646		  (SECMODE_SIGN_ENABLED|SECMODE_SIGN_REQUIRED)) == 0)
1647			return false;
1648
 
 
 
 
 
 
 
 
 
 
 
1649	return true;
1650}
1651
1652static int match_server(struct TCP_Server_Info *server, struct sockaddr *addr,
1653			 struct smb_vol *vol)
 
1654{
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1655	if (!net_eq(cifs_net_ns(server), current->nsproxy->net_ns))
1656		return 0;
1657
1658	if (!match_address(server, addr,
1659			   (struct sockaddr *)&vol->srcaddr))
1660		return 0;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1661
1662	if (!match_port(server, addr))
1663		return 0;
1664
1665	if (!match_security(server, vol))
 
 
 
 
 
 
 
 
 
1666		return 0;
1667
1668	return 1;
1669}
1670
1671static struct TCP_Server_Info *
1672cifs_find_tcp_session(struct sockaddr *addr, struct smb_vol *vol)
1673{
1674	struct TCP_Server_Info *server;
1675
1676	spin_lock(&cifs_tcp_ses_lock);
1677	list_for_each_entry(server, &cifs_tcp_ses_list, tcp_ses_list) {
1678		if (!match_server(server, addr, vol))
 
 
 
 
 
 
1679			continue;
 
 
1680
1681		++server->srv_count;
1682		spin_unlock(&cifs_tcp_ses_lock);
1683		cFYI(1, "Existing tcp session with server found");
1684		return server;
1685	}
1686	spin_unlock(&cifs_tcp_ses_lock);
1687	return NULL;
1688}
1689
1690static void
1691cifs_put_tcp_session(struct TCP_Server_Info *server)
1692{
1693	struct task_struct *task;
1694
1695	spin_lock(&cifs_tcp_ses_lock);
1696	if (--server->srv_count > 0) {
1697		spin_unlock(&cifs_tcp_ses_lock);
1698		return;
1699	}
1700
 
 
 
1701	put_net(cifs_net_ns(server));
1702
1703	list_del_init(&server->tcp_ses_list);
1704	spin_unlock(&cifs_tcp_ses_lock);
1705
 
 
 
 
1706	cancel_delayed_work_sync(&server->echo);
 
1707
1708	spin_lock(&GlobalMid_Lock);
 
 
 
 
 
 
 
 
 
 
 
1709	server->tcpStatus = CifsExiting;
1710	spin_unlock(&GlobalMid_Lock);
1711
1712	cifs_crypto_shash_release(server);
1713	cifs_fscache_release_client_cookie(server);
1714
1715	kfree(server->session_key.response);
1716	server->session_key.response = NULL;
1717	server->session_key.len = 0;
 
 
1718
1719	task = xchg(&server->tsk, NULL);
1720	if (task)
1721		force_sig(SIGKILL, task);
1722}
1723
1724static struct TCP_Server_Info *
1725cifs_get_tcp_session(struct smb_vol *volume_info)
 
1726{
1727	struct TCP_Server_Info *tcp_ses = NULL;
1728	struct sockaddr_storage addr;
1729	struct sockaddr_in *sin_server = (struct sockaddr_in *) &addr;
1730	struct sockaddr_in6 *sin_server6 = (struct sockaddr_in6 *) &addr;
1731	int rc;
1732
1733	memset(&addr, 0, sizeof(struct sockaddr_storage));
1734
1735	cFYI(1, "UNC: %s ip: %s", volume_info->UNC, volume_info->UNCip);
1736
1737	if (volume_info->UNCip && volume_info->UNC) {
1738		rc = cifs_fill_sockaddr((struct sockaddr *)&addr,
1739					volume_info->UNCip,
1740					strlen(volume_info->UNCip),
1741					volume_info->port);
1742		if (!rc) {
1743			/* we failed translating address */
1744			rc = -EINVAL;
1745			goto out_err;
1746		}
1747	} else if (volume_info->UNCip) {
1748		/* BB using ip addr as tcp_ses name to connect to the
1749		   DFS root below */
1750		cERROR(1, "Connecting to DFS root not implemented yet");
1751		rc = -EINVAL;
1752		goto out_err;
1753	} else /* which tcp_sess DFS root would we conect to */ {
1754		cERROR(1, "CIFS mount error: No UNC path (e.g. -o "
1755			"unc=//192.168.1.100/public) specified");
1756		rc = -EINVAL;
1757		goto out_err;
1758	}
1759
1760	/* see if we already have a matching tcp_ses */
1761	tcp_ses = cifs_find_tcp_session((struct sockaddr *)&addr, volume_info);
1762	if (tcp_ses)
1763		return tcp_ses;
1764
1765	tcp_ses = kzalloc(sizeof(struct TCP_Server_Info), GFP_KERNEL);
1766	if (!tcp_ses) {
1767		rc = -ENOMEM;
1768		goto out_err;
1769	}
1770
1771	rc = cifs_crypto_shash_allocate(tcp_ses);
1772	if (rc) {
1773		cERROR(1, "could not setup hash structures rc %d", rc);
1774		goto out_err;
1775	}
1776
1777	cifs_set_net_ns(tcp_ses, get_net(current->nsproxy->net_ns));
1778	tcp_ses->hostname = extract_hostname(volume_info->UNC);
1779	if (IS_ERR(tcp_ses->hostname)) {
1780		rc = PTR_ERR(tcp_ses->hostname);
1781		goto out_err_crypto_release;
 
 
1782	}
1783
1784	tcp_ses->noblocksnd = volume_info->noblocksnd;
1785	tcp_ses->noautotune = volume_info->noautotune;
1786	tcp_ses->tcp_nodelay = volume_info->sockopt_tcp_nodelay;
1787	atomic_set(&tcp_ses->inFlight, 0);
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1788	init_waitqueue_head(&tcp_ses->response_q);
1789	init_waitqueue_head(&tcp_ses->request_q);
1790	INIT_LIST_HEAD(&tcp_ses->pending_mid_q);
1791	mutex_init(&tcp_ses->srv_mutex);
1792	memcpy(tcp_ses->workstation_RFC1001_name,
1793		volume_info->source_rfc1001_name, RFC1001_NAME_LEN_WITH_NULL);
1794	memcpy(tcp_ses->server_RFC1001_name,
1795		volume_info->target_rfc1001_name, RFC1001_NAME_LEN_WITH_NULL);
1796	tcp_ses->session_estab = false;
1797	tcp_ses->sequence_number = 0;
 
1798	tcp_ses->lstrp = jiffies;
 
 
 
 
1799	INIT_LIST_HEAD(&tcp_ses->tcp_ses_list);
1800	INIT_LIST_HEAD(&tcp_ses->smb_ses_list);
1801	INIT_DELAYED_WORK(&tcp_ses->echo, cifs_echo_request);
1802
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1803	/*
1804	 * at this point we are the only ones with the pointer
1805	 * to the struct since the kernel thread not created yet
1806	 * no need to spinlock this init of tcpStatus or srv_count
1807	 */
1808	tcp_ses->tcpStatus = CifsNew;
1809	memcpy(&tcp_ses->srcaddr, &volume_info->srcaddr,
1810	       sizeof(tcp_ses->srcaddr));
1811	++tcp_ses->srv_count;
1812
1813	if (addr.ss_family == AF_INET6) {
1814		cFYI(1, "attempting ipv6 connect");
1815		/* BB should we allow ipv6 on port 139? */
1816		/* other OS never observed in Wild doing 139 with v6 */
1817		memcpy(&tcp_ses->dstaddr, sin_server6,
1818		       sizeof(struct sockaddr_in6));
1819	} else
1820		memcpy(&tcp_ses->dstaddr, sin_server,
1821		       sizeof(struct sockaddr_in));
1822
 
 
 
 
 
 
 
 
 
 
 
 
1823	rc = ip_connect(tcp_ses);
1824	if (rc < 0) {
1825		cERROR(1, "Error connecting to socket. Aborting operation");
1826		goto out_err_crypto_release;
1827	}
1828
1829	/*
1830	 * since we're in a cifs function already, we know that
1831	 * this will succeed. No need for try_module_get().
1832	 */
1833	__module_get(THIS_MODULE);
1834	tcp_ses->tsk = kthread_run(cifs_demultiplex_thread,
1835				  tcp_ses, "cifsd");
1836	if (IS_ERR(tcp_ses->tsk)) {
1837		rc = PTR_ERR(tcp_ses->tsk);
1838		cERROR(1, "error %d create cifsd thread", rc);
1839		module_put(THIS_MODULE);
1840		goto out_err_crypto_release;
1841	}
 
 
 
 
 
 
 
1842	tcp_ses->tcpStatus = CifsNeedNegotiate;
 
1843
 
 
 
 
 
 
 
1844	/* thread spawned, put it on the list */
1845	spin_lock(&cifs_tcp_ses_lock);
1846	list_add(&tcp_ses->tcp_ses_list, &cifs_tcp_ses_list);
1847	spin_unlock(&cifs_tcp_ses_lock);
1848
1849	cifs_fscache_get_client_cookie(tcp_ses);
1850
1851	/* queue echo request delayed work */
1852	queue_delayed_work(system_nrt_wq, &tcp_ses->echo, SMB_ECHO_INTERVAL);
 
 
 
 
 
 
1853
1854	return tcp_ses;
1855
1856out_err_crypto_release:
1857	cifs_crypto_shash_release(tcp_ses);
1858
1859	put_net(cifs_net_ns(tcp_ses));
1860
1861out_err:
1862	if (tcp_ses) {
1863		if (!IS_ERR(tcp_ses->hostname))
1864			kfree(tcp_ses->hostname);
 
 
1865		if (tcp_ses->ssocket)
1866			sock_release(tcp_ses->ssocket);
1867		kfree(tcp_ses);
1868	}
1869	return ERR_PTR(rc);
1870}
1871
1872static int match_session(struct cifs_ses *ses, struct smb_vol *vol)
 
1873{
1874	switch (ses->server->secType) {
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1875	case Kerberos:
1876		if (vol->cred_uid != ses->cred_uid)
1877			return 0;
1878		break;
1879	default:
 
 
 
 
 
 
 
1880		/* anything else takes username/password */
1881		if (ses->user_name == NULL)
1882			return 0;
1883		if (strncmp(ses->user_name, vol->username,
1884			    MAX_USERNAME_SIZE))
1885			return 0;
1886		if (strlen(vol->username) != 0 &&
1887		    ses->password != NULL &&
1888		    strncmp(ses->password,
1889			    vol->password ? vol->password : "",
1890			    MAX_PASSWORD_SIZE))
1891			return 0;
1892	}
1893	return 1;
1894}
1895
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1896static struct cifs_ses *
1897cifs_find_smb_ses(struct TCP_Server_Info *server, struct smb_vol *vol)
1898{
1899	struct cifs_ses *ses;
1900
1901	spin_lock(&cifs_tcp_ses_lock);
1902	list_for_each_entry(ses, &server->smb_ses_list, smb_ses_list) {
1903		if (!match_session(ses, vol))
 
 
1904			continue;
 
 
 
 
 
 
 
1905		++ses->ses_count;
1906		spin_unlock(&cifs_tcp_ses_lock);
1907		return ses;
1908	}
1909	spin_unlock(&cifs_tcp_ses_lock);
1910	return NULL;
1911}
1912
1913static void
1914cifs_put_smb_ses(struct cifs_ses *ses)
1915{
1916	int xid;
 
1917	struct TCP_Server_Info *server = ses->server;
1918
1919	cFYI(1, "%s: ses_count=%d\n", __func__, ses->ses_count);
 
 
 
 
 
 
 
 
 
 
1920	spin_lock(&cifs_tcp_ses_lock);
1921	if (--ses->ses_count > 0) {
1922		spin_unlock(&cifs_tcp_ses_lock);
1923		return;
1924	}
 
 
 
 
 
 
 
 
 
1925
 
 
 
 
 
 
 
 
 
 
1926	list_del_init(&ses->smb_ses_list);
1927	spin_unlock(&cifs_tcp_ses_lock);
1928
1929	if (ses->status == CifsGood) {
1930		xid = GetXid();
1931		CIFSSMBLogoff(xid, ses);
1932		_FreeXid(xid);
 
 
 
 
 
 
 
 
 
 
1933	}
 
1934	sesInfoFree(ses);
1935	cifs_put_tcp_session(server);
1936}
1937
1938static bool warned_on_ntlm;  /* globals init to false automatically */
1939
1940static struct cifs_ses *
1941cifs_get_smb_ses(struct TCP_Server_Info *server, struct smb_vol *volume_info)
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1942{
1943	int rc = -ENOMEM, xid;
 
1944	struct cifs_ses *ses;
1945	struct sockaddr_in *addr = (struct sockaddr_in *)&server->dstaddr;
1946	struct sockaddr_in6 *addr6 = (struct sockaddr_in6 *)&server->dstaddr;
1947
1948	xid = GetXid();
1949
1950	ses = cifs_find_smb_ses(server, volume_info);
1951	if (ses) {
1952		cFYI(1, "Existing smb sess found (status=%d)", ses->status);
 
1953
1954		mutex_lock(&ses->session_mutex);
1955		rc = cifs_negotiate_protocol(xid, ses);
1956		if (rc) {
1957			mutex_unlock(&ses->session_mutex);
1958			/* problem -- put our ses reference */
1959			cifs_put_smb_ses(ses);
1960			FreeXid(xid);
1961			return ERR_PTR(rc);
1962		}
1963		if (ses->need_reconnect) {
1964			cFYI(1, "Session needs reconnect");
1965			rc = cifs_setup_session(xid, ses,
1966						volume_info->local_nls);
 
 
 
 
1967			if (rc) {
1968				mutex_unlock(&ses->session_mutex);
1969				/* problem -- put our reference */
1970				cifs_put_smb_ses(ses);
1971				FreeXid(xid);
1972				return ERR_PTR(rc);
1973			}
 
 
 
1974		}
1975		mutex_unlock(&ses->session_mutex);
1976
1977		/* existing SMB ses has a server reference already */
1978		cifs_put_tcp_session(server);
1979		FreeXid(xid);
1980		return ses;
1981	}
1982
1983	cFYI(1, "Existing smb sess not found");
 
 
1984	ses = sesInfoAlloc();
1985	if (ses == NULL)
1986		goto get_ses_fail;
1987
1988	/* new SMB session uses our server ref */
1989	ses->server = server;
1990	if (server->dstaddr.ss_family == AF_INET6)
1991		sprintf(ses->serverName, "%pI6", &addr6->sin6_addr);
1992	else
1993		sprintf(ses->serverName, "%pI4", &addr->sin_addr);
1994
1995	if (volume_info->username) {
1996		ses->user_name = kstrdup(volume_info->username, GFP_KERNEL);
1997		if (!ses->user_name)
1998			goto get_ses_fail;
1999	}
2000
2001	/* volume_info->password freed at unmount */
2002	if (volume_info->password) {
2003		ses->password = kstrdup(volume_info->password, GFP_KERNEL);
2004		if (!ses->password)
2005			goto get_ses_fail;
2006	}
2007	if (volume_info->domainname) {
2008		ses->domainName = kstrdup(volume_info->domainname, GFP_KERNEL);
2009		if (!ses->domainName)
2010			goto get_ses_fail;
2011	}
2012	ses->cred_uid = volume_info->cred_uid;
2013	ses->linux_uid = volume_info->linux_uid;
2014
2015	/* ntlmv2 is much stronger than ntlm security, and has been broadly
2016	supported for many years, time to update default security mechanism */
2017	if ((volume_info->secFlg == 0) && warned_on_ntlm == false) {
2018		warned_on_ntlm = true;
2019		cERROR(1, "default security mechanism requested.  The default "
2020			"security mechanism will be upgraded from ntlm to "
2021			"ntlmv2 in kernel release 3.2");
2022	}
2023	ses->overrideSecFlg = volume_info->secFlg;
 
 
 
 
 
 
 
 
2024
2025	mutex_lock(&ses->session_mutex);
2026	rc = cifs_negotiate_protocol(xid, ses);
2027	if (!rc)
2028		rc = cifs_setup_session(xid, ses, volume_info->local_nls);
2029	mutex_unlock(&ses->session_mutex);
 
 
 
 
 
 
 
2030	if (rc)
2031		goto get_ses_fail;
2032
2033	/* success, put it on the list */
 
 
 
 
2034	spin_lock(&cifs_tcp_ses_lock);
2035	list_add(&ses->smb_ses_list, &server->smb_ses_list);
2036	spin_unlock(&cifs_tcp_ses_lock);
2037
2038	FreeXid(xid);
 
 
 
2039	return ses;
2040
2041get_ses_fail:
2042	sesInfoFree(ses);
2043	FreeXid(xid);
2044	return ERR_PTR(rc);
2045}
2046
2047static int match_tcon(struct cifs_tcon *tcon, const char *unc)
 
2048{
2049	if (tcon->tidStatus == CifsExiting)
 
 
 
 
 
 
 
2050		return 0;
2051	if (strncmp(tcon->treeName, unc, MAX_TREE_SIZE))
 
 
 
 
2052		return 0;
2053	return 1;
2054}
2055
2056static struct cifs_tcon *
2057cifs_find_tcon(struct cifs_ses *ses, const char *unc)
2058{
2059	struct list_head *tmp;
2060	struct cifs_tcon *tcon;
2061
2062	spin_lock(&cifs_tcp_ses_lock);
2063	list_for_each(tmp, &ses->tcon_list) {
2064		tcon = list_entry(tmp, struct cifs_tcon, tcon_list);
2065		if (!match_tcon(tcon, unc))
 
2066			continue;
 
2067		++tcon->tc_count;
 
2068		spin_unlock(&cifs_tcp_ses_lock);
2069		return tcon;
2070	}
2071	spin_unlock(&cifs_tcp_ses_lock);
2072	return NULL;
2073}
2074
2075static void
2076cifs_put_tcon(struct cifs_tcon *tcon)
2077{
2078	int xid;
2079	struct cifs_ses *ses = tcon->ses;
2080
2081	cFYI(1, "%s: tc_count=%d\n", __func__, tcon->tc_count);
 
 
 
 
 
 
 
 
2082	spin_lock(&cifs_tcp_ses_lock);
 
2083	if (--tcon->tc_count > 0) {
 
2084		spin_unlock(&cifs_tcp_ses_lock);
2085		return;
2086	}
2087
 
 
 
2088	list_del_init(&tcon->tcon_list);
 
2089	spin_unlock(&cifs_tcp_ses_lock);
2090
2091	xid = GetXid();
2092	CIFSSMBTDis(xid, tcon);
2093	_FreeXid(xid);
 
 
 
 
 
 
 
 
 
 
 
 
 
 
2094
2095	cifs_fscache_release_super_cookie(tcon);
2096	tconInfoFree(tcon);
2097	cifs_put_smb_ses(ses);
2098}
2099
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
2100static struct cifs_tcon *
2101cifs_get_tcon(struct cifs_ses *ses, struct smb_vol *volume_info)
2102{
2103	int rc, xid;
2104	struct cifs_tcon *tcon;
2105
2106	tcon = cifs_find_tcon(ses, volume_info->UNC);
2107	if (tcon) {
2108		cFYI(1, "Found match on UNC path");
2109		/* existing tcon already has a reference */
 
 
 
2110		cifs_put_smb_ses(ses);
2111		if (tcon->seal != volume_info->seal)
2112			cERROR(1, "transport encryption setting "
2113				   "conflicts with existing tid");
2114		return tcon;
2115	}
2116
 
 
 
 
 
2117	tcon = tconInfoAlloc();
2118	if (tcon == NULL) {
2119		rc = -ENOMEM;
2120		goto out_fail;
2121	}
2122
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
2123	tcon->ses = ses;
2124	if (volume_info->password) {
2125		tcon->password = kstrdup(volume_info->password, GFP_KERNEL);
2126		if (!tcon->password) {
2127			rc = -ENOMEM;
2128			goto out_fail;
2129		}
2130	}
2131
2132	if (strchr(volume_info->UNC + 3, '\\') == NULL
2133	    && strchr(volume_info->UNC + 3, '/') == NULL) {
2134		cERROR(1, "Missing share name");
2135		rc = -ENODEV;
2136		goto out_fail;
 
 
 
 
 
 
 
 
 
2137	}
2138
2139	/* BB Do we need to wrap session_mutex around
2140	 * this TCon call and Unix SetFS as
2141	 * we do on SessSetup and reconnect? */
2142	xid = GetXid();
2143	rc = CIFSTCon(xid, ses, volume_info->UNC, tcon, volume_info->local_nls);
2144	FreeXid(xid);
2145	cFYI(1, "CIFS Tcon rc = %d", rc);
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
2146	if (rc)
2147		goto out_fail;
2148
2149	if (volume_info->nodfs) {
2150		tcon->Flags &= ~SMB_SHARE_IS_IN_DFS;
2151		cFYI(1, "DFS disabled (%d)", tcon->Flags);
2152	}
2153	tcon->seal = volume_info->seal;
2154	/* we can have only one retry value for a connection
2155	   to a share so for resources mounted more than once
2156	   to the same server share the last value passed in
2157	   for the retry flag is used */
2158	tcon->retry = volume_info->retry;
2159	tcon->nocase = volume_info->nocase;
2160	tcon->local_lease = volume_info->local_lease;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
2161
2162	spin_lock(&cifs_tcp_ses_lock);
2163	list_add(&tcon->tcon_list, &ses->tcon_list);
2164	spin_unlock(&cifs_tcp_ses_lock);
2165
2166	cifs_fscache_get_super_cookie(tcon);
2167
2168	return tcon;
2169
2170out_fail:
2171	tconInfoFree(tcon);
2172	return ERR_PTR(rc);
2173}
2174
2175void
2176cifs_put_tlink(struct tcon_link *tlink)
2177{
2178	if (!tlink || IS_ERR(tlink))
2179		return;
2180
2181	if (!atomic_dec_and_test(&tlink->tl_count) ||
2182	    test_bit(TCON_LINK_IN_TREE, &tlink->tl_flags)) {
2183		tlink->tl_time = jiffies;
2184		return;
2185	}
2186
2187	if (!IS_ERR(tlink_tcon(tlink)))
2188		cifs_put_tcon(tlink_tcon(tlink));
2189	kfree(tlink);
2190	return;
2191}
2192
2193static inline struct tcon_link *
2194cifs_sb_master_tlink(struct cifs_sb_info *cifs_sb)
2195{
2196	return cifs_sb->master_tlink;
2197}
2198
2199static int
2200compare_mount_options(struct super_block *sb, struct cifs_mnt_data *mnt_data)
2201{
2202	struct cifs_sb_info *old = CIFS_SB(sb);
2203	struct cifs_sb_info *new = mnt_data->cifs_sb;
 
 
2204
2205	if ((sb->s_flags & CIFS_MS_MASK) != (mnt_data->flags & CIFS_MS_MASK))
2206		return 0;
2207
2208	if ((old->mnt_cifs_flags & CIFS_MOUNT_MASK) !=
2209	    (new->mnt_cifs_flags & CIFS_MOUNT_MASK))
2210		return 0;
2211
2212	if (old->rsize != new->rsize)
2213		return 0;
2214
2215	/*
2216	 * We want to share sb only if we don't specify wsize or specified wsize
2217	 * is greater or equal than existing one.
2218	 */
2219	if (new->wsize && new->wsize < old->wsize)
 
 
 
2220		return 0;
2221
2222	if (old->mnt_uid != new->mnt_uid || old->mnt_gid != new->mnt_gid)
 
2223		return 0;
2224
2225	if (old->mnt_file_mode != new->mnt_file_mode ||
2226	    old->mnt_dir_mode != new->mnt_dir_mode)
2227		return 0;
2228
2229	if (strcmp(old->local_nls->charset, new->local_nls->charset))
2230		return 0;
2231
2232	if (old->actimeo != new->actimeo)
 
 
 
 
2233		return 0;
2234
2235	return 1;
2236}
2237
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
2238int
2239cifs_match_super(struct super_block *sb, void *data)
2240{
2241	struct cifs_mnt_data *mnt_data = (struct cifs_mnt_data *)data;
2242	struct smb_vol *volume_info;
2243	struct cifs_sb_info *cifs_sb;
2244	struct TCP_Server_Info *tcp_srv;
2245	struct cifs_ses *ses;
2246	struct cifs_tcon *tcon;
2247	struct tcon_link *tlink;
2248	struct sockaddr_storage addr;
2249	int rc = 0;
2250
2251	memset(&addr, 0, sizeof(struct sockaddr_storage));
2252
2253	spin_lock(&cifs_tcp_ses_lock);
2254	cifs_sb = CIFS_SB(sb);
2255	tlink = cifs_get_tlink(cifs_sb_master_tlink(cifs_sb));
2256	if (IS_ERR(tlink)) {
 
2257		spin_unlock(&cifs_tcp_ses_lock);
2258		return rc;
2259	}
2260	tcon = tlink_tcon(tlink);
2261	ses = tcon->ses;
2262	tcp_srv = ses->server;
2263
2264	volume_info = mnt_data->vol;
2265
2266	if (!volume_info->UNCip || !volume_info->UNC)
2267		goto out;
2268
2269	rc = cifs_fill_sockaddr((struct sockaddr *)&addr,
2270				volume_info->UNCip,
2271				strlen(volume_info->UNCip),
2272				volume_info->port);
2273	if (!rc)
2274		goto out;
2275
2276	if (!match_server(tcp_srv, (struct sockaddr *)&addr, volume_info) ||
2277	    !match_session(ses, volume_info) ||
2278	    !match_tcon(tcon, volume_info->UNC)) {
 
 
 
 
2279		rc = 0;
2280		goto out;
2281	}
2282
2283	rc = compare_mount_options(sb, mnt_data);
2284out:
 
 
 
 
2285	spin_unlock(&cifs_tcp_ses_lock);
2286	cifs_put_tlink(tlink);
2287	return rc;
2288}
2289
2290int
2291get_dfs_path(int xid, struct cifs_ses *pSesInfo, const char *old_path,
2292	     const struct nls_table *nls_codepage, unsigned int *pnum_referrals,
2293	     struct dfs_info3_param **preferrals, int remap)
2294{
2295	char *temp_unc;
2296	int rc = 0;
2297
2298	*pnum_referrals = 0;
2299	*preferrals = NULL;
2300
2301	if (pSesInfo->ipc_tid == 0) {
2302		temp_unc = kmalloc(2 /* for slashes */ +
2303			strnlen(pSesInfo->serverName,
2304				SERVER_NAME_LEN_WITH_NULL * 2)
2305				 + 1 + 4 /* slash IPC$ */  + 2,
2306				GFP_KERNEL);
2307		if (temp_unc == NULL)
2308			return -ENOMEM;
2309		temp_unc[0] = '\\';
2310		temp_unc[1] = '\\';
2311		strcpy(temp_unc + 2, pSesInfo->serverName);
2312		strcpy(temp_unc + 2 + strlen(pSesInfo->serverName), "\\IPC$");
2313		rc = CIFSTCon(xid, pSesInfo, temp_unc, NULL, nls_codepage);
2314		cFYI(1, "CIFS Tcon rc = %d ipc_tid = %d", rc, pSesInfo->ipc_tid);
2315		kfree(temp_unc);
2316	}
2317	if (rc == 0)
2318		rc = CIFSGetDFSRefer(xid, pSesInfo, old_path, preferrals,
2319				     pnum_referrals, nls_codepage, remap);
2320	/* BB map targetUNCs to dfs_info3 structures, here or
2321		in CIFSGetDFSRefer BB */
2322
2323	return rc;
2324}
2325
2326#ifdef CONFIG_DEBUG_LOCK_ALLOC
2327static struct lock_class_key cifs_key[2];
2328static struct lock_class_key cifs_slock_key[2];
2329
2330static inline void
2331cifs_reclassify_socket4(struct socket *sock)
2332{
2333	struct sock *sk = sock->sk;
2334	BUG_ON(sock_owned_by_user(sk));
2335	sock_lock_init_class_and_name(sk, "slock-AF_INET-CIFS",
2336		&cifs_slock_key[0], "sk_lock-AF_INET-CIFS", &cifs_key[0]);
2337}
2338
2339static inline void
2340cifs_reclassify_socket6(struct socket *sock)
2341{
2342	struct sock *sk = sock->sk;
2343	BUG_ON(sock_owned_by_user(sk));
2344	sock_lock_init_class_and_name(sk, "slock-AF_INET6-CIFS",
2345		&cifs_slock_key[1], "sk_lock-AF_INET6-CIFS", &cifs_key[1]);
2346}
2347#else
2348static inline void
2349cifs_reclassify_socket4(struct socket *sock)
2350{
2351}
2352
2353static inline void
2354cifs_reclassify_socket6(struct socket *sock)
2355{
2356}
2357#endif
2358
2359/* See RFC1001 section 14 on representation of Netbios names */
2360static void rfc1002mangle(char *target, char *source, unsigned int length)
2361{
2362	unsigned int i, j;
2363
2364	for (i = 0, j = 0; i < (length); i++) {
2365		/* mask a nibble at a time and encode */
2366		target[j] = 'A' + (0x0F & (source[i] >> 4));
2367		target[j+1] = 'A' + (0x0F & source[i]);
2368		j += 2;
2369	}
2370
2371}
2372
2373static int
2374bind_socket(struct TCP_Server_Info *server)
2375{
2376	int rc = 0;
2377	if (server->srcaddr.ss_family != AF_UNSPEC) {
2378		/* Bind to the specified local IP address */
2379		struct socket *socket = server->ssocket;
2380		rc = socket->ops->bind(socket,
2381				       (struct sockaddr *) &server->srcaddr,
2382				       sizeof(server->srcaddr));
2383		if (rc < 0) {
2384			struct sockaddr_in *saddr4;
2385			struct sockaddr_in6 *saddr6;
2386			saddr4 = (struct sockaddr_in *)&server->srcaddr;
2387			saddr6 = (struct sockaddr_in6 *)&server->srcaddr;
2388			if (saddr6->sin6_family == AF_INET6)
2389				cERROR(1, "cifs: "
2390				       "Failed to bind to: %pI6c, error: %d\n",
2391				       &saddr6->sin6_addr, rc);
2392			else
2393				cERROR(1, "cifs: "
2394				       "Failed to bind to: %pI4, error: %d\n",
2395				       &saddr4->sin_addr.s_addr, rc);
2396		}
2397	}
2398	return rc;
2399}
2400
2401static int
2402ip_rfc1001_connect(struct TCP_Server_Info *server)
2403{
2404	int rc = 0;
2405	/*
2406	 * some servers require RFC1001 sessinit before sending
2407	 * negprot - BB check reconnection in case where second
2408	 * sessinit is sent but no second negprot
2409	 */
2410	struct rfc1002_session_packet *ses_init_buf;
 
2411	struct smb_hdr *smb_buf;
 
2412	ses_init_buf = kzalloc(sizeof(struct rfc1002_session_packet),
2413			       GFP_KERNEL);
 
2414	if (ses_init_buf) {
2415		ses_init_buf->trailer.session_req.called_len = 32;
2416
2417		if (server->server_RFC1001_name &&
2418		    server->server_RFC1001_name[0] != 0)
2419			rfc1002mangle(ses_init_buf->trailer.
2420				      session_req.called_name,
2421				      server->server_RFC1001_name,
2422				      RFC1001_NAME_LEN_WITH_NULL);
2423		else
2424			rfc1002mangle(ses_init_buf->trailer.
2425				      session_req.called_name,
2426				      DEFAULT_CIFS_CALLED_NAME,
2427				      RFC1001_NAME_LEN_WITH_NULL);
2428
2429		ses_init_buf->trailer.session_req.calling_len = 32;
2430
2431		/*
2432		 * calling name ends in null (byte 16) from old smb
2433		 * convention.
2434		 */
2435		if (server->workstation_RFC1001_name &&
2436		    server->workstation_RFC1001_name[0] != 0)
2437			rfc1002mangle(ses_init_buf->trailer.
2438				      session_req.calling_name,
2439				      server->workstation_RFC1001_name,
2440				      RFC1001_NAME_LEN_WITH_NULL);
2441		else
2442			rfc1002mangle(ses_init_buf->trailer.
2443				      session_req.calling_name,
2444				      "LINUX_CIFS_CLNT",
2445				      RFC1001_NAME_LEN_WITH_NULL);
2446
2447		ses_init_buf->trailer.session_req.scope1 = 0;
2448		ses_init_buf->trailer.session_req.scope2 = 0;
2449		smb_buf = (struct smb_hdr *)ses_init_buf;
2450
2451		/* sizeof RFC1002_SESSION_REQUEST with no scope */
2452		smb_buf->smb_buf_length = cpu_to_be32(0x81000044);
 
 
 
 
2453		rc = smb_send(server, smb_buf, 0x44);
2454		kfree(ses_init_buf);
2455		/*
2456		 * RFC1001 layer in at least one server
2457		 * requires very short break before negprot
2458		 * presumably because not expecting negprot
2459		 * to follow so fast.  This is a simple
2460		 * solution that works without
2461		 * complicating the code and causes no
2462		 * significant slowing down on mount
2463		 * for everyone else
2464		 */
2465		usleep_range(1000, 2000);
2466	}
2467	/*
2468	 * else the negprot may still work without this
2469	 * even though malloc failed
2470	 */
2471
2472	return rc;
2473}
2474
2475static int
2476generic_ip_connect(struct TCP_Server_Info *server)
2477{
2478	int rc = 0;
2479	__be16 sport;
2480	int slen, sfamily;
2481	struct socket *socket = server->ssocket;
2482	struct sockaddr *saddr;
2483
2484	saddr = (struct sockaddr *) &server->dstaddr;
2485
2486	if (server->dstaddr.ss_family == AF_INET6) {
2487		sport = ((struct sockaddr_in6 *) saddr)->sin6_port;
 
 
2488		slen = sizeof(struct sockaddr_in6);
2489		sfamily = AF_INET6;
 
 
2490	} else {
2491		sport = ((struct sockaddr_in *) saddr)->sin_port;
 
 
2492		slen = sizeof(struct sockaddr_in);
2493		sfamily = AF_INET;
 
 
2494	}
2495
2496	if (socket == NULL) {
2497		rc = __sock_create(cifs_net_ns(server), sfamily, SOCK_STREAM,
2498				   IPPROTO_TCP, &socket, 1);
2499		if (rc < 0) {
2500			cERROR(1, "Error %d creating socket", rc);
2501			server->ssocket = NULL;
2502			return rc;
2503		}
2504
2505		/* BB other socket options to set KEEPALIVE, NODELAY? */
2506		cFYI(1, "Socket created");
2507		server->ssocket = socket;
2508		socket->sk->sk_allocation = GFP_NOFS;
 
2509		if (sfamily == AF_INET6)
2510			cifs_reclassify_socket6(socket);
2511		else
2512			cifs_reclassify_socket4(socket);
2513	}
2514
2515	rc = bind_socket(server);
2516	if (rc < 0)
2517		return rc;
2518
2519	/*
2520	 * Eventually check for other socket options to change from
2521	 * the default. sock_setsockopt not used because it expects
2522	 * user space buffer
2523	 */
2524	socket->sk->sk_rcvtimeo = 7 * HZ;
2525	socket->sk->sk_sndtimeo = 5 * HZ;
2526
2527	/* make the bufsizes depend on wsize/rsize and max requests */
2528	if (server->noautotune) {
2529		if (socket->sk->sk_sndbuf < (200 * 1024))
2530			socket->sk->sk_sndbuf = 200 * 1024;
2531		if (socket->sk->sk_rcvbuf < (140 * 1024))
2532			socket->sk->sk_rcvbuf = 140 * 1024;
2533	}
2534
2535	if (server->tcp_nodelay) {
2536		int val = 1;
2537		rc = kernel_setsockopt(socket, SOL_TCP, TCP_NODELAY,
2538				(char *)&val, sizeof(val));
2539		if (rc)
2540			cFYI(1, "set TCP_NODELAY socket option error %d", rc);
2541	}
2542
2543	 cFYI(1, "sndbuf %d rcvbuf %d rcvtimeo 0x%lx",
2544		 socket->sk->sk_sndbuf,
2545		 socket->sk->sk_rcvbuf, socket->sk->sk_rcvtimeo);
2546
2547	rc = socket->ops->connect(socket, saddr, slen, 0);
 
 
 
 
 
 
 
 
2548	if (rc < 0) {
2549		cFYI(1, "Error %d connecting to server", rc);
 
2550		sock_release(socket);
2551		server->ssocket = NULL;
2552		return rc;
2553	}
2554
2555	if (sport == htons(RFC1001_PORT))
2556		rc = ip_rfc1001_connect(server);
2557
2558	return rc;
2559}
2560
2561static int
2562ip_connect(struct TCP_Server_Info *server)
2563{
2564	__be16 *sport;
2565	struct sockaddr_in6 *addr6 = (struct sockaddr_in6 *)&server->dstaddr;
2566	struct sockaddr_in *addr = (struct sockaddr_in *)&server->dstaddr;
2567
2568	if (server->dstaddr.ss_family == AF_INET6)
2569		sport = &addr6->sin6_port;
2570	else
2571		sport = &addr->sin_port;
2572
2573	if (*sport == 0) {
2574		int rc;
2575
2576		/* try with 445 port at first */
2577		*sport = htons(CIFS_PORT);
2578
2579		rc = generic_ip_connect(server);
2580		if (rc >= 0)
2581			return rc;
2582
2583		/* if it failed, try with 139 port */
2584		*sport = htons(RFC1001_PORT);
2585	}
2586
2587	return generic_ip_connect(server);
2588}
2589
2590void reset_cifs_unix_caps(int xid, struct cifs_tcon *tcon,
2591			  struct cifs_sb_info *cifs_sb, struct smb_vol *vol_info)
 
2592{
2593	/* if we are reconnecting then should we check to see if
 
2594	 * any requested capabilities changed locally e.g. via
2595	 * remount but we can not do much about it here
2596	 * if they have (even if we could detect it by the following)
2597	 * Perhaps we could add a backpointer to array of sb from tcon
2598	 * or if we change to make all sb to same share the same
2599	 * sb as NFS - then we only have one backpointer to sb.
2600	 * What if we wanted to mount the server share twice once with
2601	 * and once without posixacls or posix paths? */
 
2602	__u64 saved_cap = le64_to_cpu(tcon->fsUnixInfo.Capability);
2603
2604	if (vol_info && vol_info->no_linux_ext) {
2605		tcon->fsUnixInfo.Capability = 0;
2606		tcon->unix_ext = 0; /* Unix Extensions disabled */
2607		cFYI(1, "Linux protocol extensions disabled");
2608		return;
2609	} else if (vol_info)
2610		tcon->unix_ext = 1; /* Unix Extensions supported */
2611
2612	if (tcon->unix_ext == 0) {
2613		cFYI(1, "Unix extensions disabled so not set on reconnect");
2614		return;
2615	}
2616
2617	if (!CIFSSMBQFSUnixInfo(xid, tcon)) {
2618		__u64 cap = le64_to_cpu(tcon->fsUnixInfo.Capability);
2619		cFYI(1, "unix caps which server supports %lld", cap);
2620		/* check for reconnect case in which we do not
2621		   want to change the mount behavior if we can avoid it */
2622		if (vol_info == NULL) {
2623			/* turn off POSIX ACL and PATHNAMES if not set
2624			   originally at mount time */
 
 
 
 
2625			if ((saved_cap & CIFS_UNIX_POSIX_ACL_CAP) == 0)
2626				cap &= ~CIFS_UNIX_POSIX_ACL_CAP;
2627			if ((saved_cap & CIFS_UNIX_POSIX_PATHNAMES_CAP) == 0) {
2628				if (cap & CIFS_UNIX_POSIX_PATHNAMES_CAP)
2629					cERROR(1, "POSIXPATH support change");
2630				cap &= ~CIFS_UNIX_POSIX_PATHNAMES_CAP;
2631			} else if ((cap & CIFS_UNIX_POSIX_PATHNAMES_CAP) == 0) {
2632				cERROR(1, "possible reconnect error");
2633				cERROR(1, "server disabled POSIX path support");
2634			}
2635		}
2636
2637		if (cap & CIFS_UNIX_TRANSPORT_ENCRYPTION_MANDATORY_CAP)
2638			cERROR(1, "per-share encryption not supported yet");
2639
2640		cap &= CIFS_UNIX_CAP_MASK;
2641		if (vol_info && vol_info->no_psx_acl)
2642			cap &= ~CIFS_UNIX_POSIX_ACL_CAP;
2643		else if (CIFS_UNIX_POSIX_ACL_CAP & cap) {
2644			cFYI(1, "negotiated posix acl support");
2645			if (cifs_sb)
2646				cifs_sb->mnt_cifs_flags |=
2647					CIFS_MOUNT_POSIXACL;
2648		}
2649
2650		if (vol_info && vol_info->posix_paths == 0)
2651			cap &= ~CIFS_UNIX_POSIX_PATHNAMES_CAP;
2652		else if (cap & CIFS_UNIX_POSIX_PATHNAMES_CAP) {
2653			cFYI(1, "negotiate posix pathnames");
2654			if (cifs_sb)
2655				cifs_sb->mnt_cifs_flags |=
2656					CIFS_MOUNT_POSIX_PATHS;
2657		}
2658
2659		if (cifs_sb && (cifs_sb->rsize > 127 * 1024)) {
2660			if ((cap & CIFS_UNIX_LARGE_READ_CAP) == 0) {
2661				cifs_sb->rsize = 127 * 1024;
2662				cFYI(DBG2, "larger reads not supported by srv");
2663			}
2664		}
2665
2666
2667		cFYI(1, "Negotiate caps 0x%x", (int)cap);
2668#ifdef CONFIG_CIFS_DEBUG2
2669		if (cap & CIFS_UNIX_FCNTL_CAP)
2670			cFYI(1, "FCNTL cap");
2671		if (cap & CIFS_UNIX_EXTATTR_CAP)
2672			cFYI(1, "EXTATTR cap");
2673		if (cap & CIFS_UNIX_POSIX_PATHNAMES_CAP)
2674			cFYI(1, "POSIX path cap");
2675		if (cap & CIFS_UNIX_XATTR_CAP)
2676			cFYI(1, "XATTR cap");
2677		if (cap & CIFS_UNIX_POSIX_ACL_CAP)
2678			cFYI(1, "POSIX ACL cap");
2679		if (cap & CIFS_UNIX_LARGE_READ_CAP)
2680			cFYI(1, "very large read cap");
2681		if (cap & CIFS_UNIX_LARGE_WRITE_CAP)
2682			cFYI(1, "very large write cap");
2683		if (cap & CIFS_UNIX_TRANSPORT_ENCRYPTION_CAP)
2684			cFYI(1, "transport encryption cap");
2685		if (cap & CIFS_UNIX_TRANSPORT_ENCRYPTION_MANDATORY_CAP)
2686			cFYI(1, "mandatory transport encryption cap");
2687#endif /* CIFS_DEBUG2 */
2688		if (CIFSSMBSetFSUnixInfo(xid, tcon, cap)) {
2689			if (vol_info == NULL) {
2690				cFYI(1, "resetting capabilities failed");
2691			} else
2692				cERROR(1, "Negotiating Unix capabilities "
2693					   "with the server failed.  Consider "
2694					   "mounting with the Unix Extensions\n"
2695					   "disabled, if problems are found, "
2696					   "by specifying the nounix mount "
2697					   "option.");
2698
2699		}
2700	}
2701}
 
2702
2703void cifs_setup_cifs_sb(struct smb_vol *pvolume_info,
2704			struct cifs_sb_info *cifs_sb)
2705{
 
 
2706	INIT_DELAYED_WORK(&cifs_sb->prune_tlinks, cifs_prune_tlinks);
2707
2708	spin_lock_init(&cifs_sb->tlink_tree_lock);
2709	cifs_sb->tlink_tree = RB_ROOT;
2710
2711	if (pvolume_info->rsize > CIFSMaxBufSize) {
2712		cERROR(1, "rsize %d too large, using MaxBufSize",
2713			pvolume_info->rsize);
2714		cifs_sb->rsize = CIFSMaxBufSize;
2715	} else if ((pvolume_info->rsize) &&
2716			(pvolume_info->rsize <= CIFSMaxBufSize))
2717		cifs_sb->rsize = pvolume_info->rsize;
2718	else /* default */
2719		cifs_sb->rsize = CIFSMaxBufSize;
2720
2721	if (cifs_sb->rsize < 2048) {
2722		cifs_sb->rsize = 2048;
2723		/* Windows ME may prefer this */
2724		cFYI(1, "readsize set to minimum: 2048");
2725	}
2726
2727	/*
2728	 * Temporarily set wsize for matching superblock. If we end up using
2729	 * new sb then cifs_negotiate_wsize will later negotiate it downward
2730	 * if needed.
2731	 */
2732	cifs_sb->wsize = pvolume_info->wsize;
2733
2734	cifs_sb->mnt_uid = pvolume_info->linux_uid;
2735	cifs_sb->mnt_gid = pvolume_info->linux_gid;
2736	cifs_sb->mnt_file_mode = pvolume_info->file_mode;
2737	cifs_sb->mnt_dir_mode = pvolume_info->dir_mode;
2738	cFYI(1, "file mode: 0x%x  dir mode: 0x%x",
2739		cifs_sb->mnt_file_mode, cifs_sb->mnt_dir_mode);
2740
2741	cifs_sb->actimeo = pvolume_info->actimeo;
2742	cifs_sb->local_nls = pvolume_info->local_nls;
2743
2744	if (pvolume_info->noperm)
2745		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_NO_PERM;
2746	if (pvolume_info->setuids)
2747		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_SET_UID;
2748	if (pvolume_info->server_ino)
2749		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_SERVER_INUM;
2750	if (pvolume_info->remap)
2751		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_MAP_SPECIAL_CHR;
2752	if (pvolume_info->no_xattr)
2753		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_NO_XATTR;
2754	if (pvolume_info->sfu_emul)
2755		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_UNX_EMUL;
2756	if (pvolume_info->nobrl)
2757		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_NO_BRL;
2758	if (pvolume_info->nostrictsync)
2759		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_NOSSYNC;
2760	if (pvolume_info->mand_lock)
2761		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_NOPOSIXBRL;
2762	if (pvolume_info->rwpidforward)
2763		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_RWPIDFORWARD;
2764	if (pvolume_info->cifs_acl)
2765		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_CIFS_ACL;
2766	if (pvolume_info->override_uid)
2767		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_OVERR_UID;
2768	if (pvolume_info->override_gid)
2769		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_OVERR_GID;
2770	if (pvolume_info->dynperm)
2771		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_DYNPERM;
2772	if (pvolume_info->fsc)
2773		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_FSCACHE;
2774	if (pvolume_info->multiuser)
2775		cifs_sb->mnt_cifs_flags |= (CIFS_MOUNT_MULTIUSER |
2776					    CIFS_MOUNT_NO_PERM);
2777	if (pvolume_info->strict_io)
2778		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_STRICT_IO;
2779	if (pvolume_info->direct_io) {
2780		cFYI(1, "mounting share using direct i/o");
2781		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_DIRECT_IO;
2782	}
2783	if (pvolume_info->mfsymlinks) {
2784		if (pvolume_info->sfu_emul) {
2785			cERROR(1,  "mount option mfsymlinks ignored if sfu "
2786				   "mount option is used");
2787		} else {
2788			cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_MF_SYMLINKS;
2789		}
2790	}
 
2791
2792	if ((pvolume_info->cifs_acl) && (pvolume_info->dynperm))
2793		cERROR(1, "mount option dynperm ignored if cifsacl "
2794			   "mount option supported");
2795}
2796
2797/*
2798 * When the server supports very large writes via POSIX extensions, we can
2799 * allow up to 2^24-1, minus the size of a WRITE_AND_X header, not including
2800 * the RFC1001 length.
2801 *
2802 * Note that this might make for "interesting" allocation problems during
2803 * writeback however as we have to allocate an array of pointers for the
2804 * pages. A 16M write means ~32kb page array with PAGE_CACHE_SIZE == 4096.
2805 */
2806#define CIFS_MAX_WSIZE ((1<<24) - 1 - sizeof(WRITE_REQ) + 4)
2807
2808/*
2809 * When the server doesn't allow large posix writes, only allow a wsize of
2810 * 128k minus the size of the WRITE_AND_X header. That allows for a write up
2811 * to the maximum size described by RFC1002.
2812 */
2813#define CIFS_MAX_RFC1002_WSIZE (128 * 1024 - sizeof(WRITE_REQ) + 4)
2814
2815/*
2816 * The default wsize is 1M. find_get_pages seems to return a maximum of 256
2817 * pages in a single call. With PAGE_CACHE_SIZE == 4k, this means we can fill
2818 * a single wsize request with a single call.
2819 */
2820#define CIFS_DEFAULT_WSIZE (1024 * 1024)
2821
2822static unsigned int
2823cifs_negotiate_wsize(struct cifs_tcon *tcon, struct smb_vol *pvolume_info)
2824{
2825	__u64 unix_cap = le64_to_cpu(tcon->fsUnixInfo.Capability);
2826	struct TCP_Server_Info *server = tcon->ses->server;
2827	unsigned int wsize = pvolume_info->wsize ? pvolume_info->wsize :
2828				CIFS_DEFAULT_WSIZE;
2829
2830	/* can server support 24-bit write sizes? (via UNIX extensions) */
2831	if (!tcon->unix_ext || !(unix_cap & CIFS_UNIX_LARGE_WRITE_CAP))
2832		wsize = min_t(unsigned int, wsize, CIFS_MAX_RFC1002_WSIZE);
2833
2834	/*
2835	 * no CAP_LARGE_WRITE_X or is signing enabled without CAP_UNIX set?
2836	 * Limit it to max buffer offered by the server, minus the size of the
2837	 * WRITEX header, not including the 4 byte RFC1001 length.
2838	 */
2839	if (!(server->capabilities & CAP_LARGE_WRITE_X) ||
2840	    (!(server->capabilities & CAP_UNIX) &&
2841	     (server->sec_mode & (SECMODE_SIGN_ENABLED|SECMODE_SIGN_REQUIRED))))
2842		wsize = min_t(unsigned int, wsize,
2843				server->maxBuf - sizeof(WRITE_REQ) + 4);
2844
2845	/* hard limit of CIFS_MAX_WSIZE */
2846	wsize = min_t(unsigned int, wsize, CIFS_MAX_WSIZE);
2847
2848	return wsize;
2849}
2850
2851static int
2852is_path_accessible(int xid, struct cifs_tcon *tcon,
2853		   struct cifs_sb_info *cifs_sb, const char *full_path)
2854{
2855	int rc;
2856	FILE_ALL_INFO *pfile_info;
2857
2858	pfile_info = kmalloc(sizeof(FILE_ALL_INFO), GFP_KERNEL);
2859	if (pfile_info == NULL)
2860		return -ENOMEM;
2861
2862	rc = CIFSSMBQPathInfo(xid, tcon, full_path, pfile_info,
2863			      0 /* not legacy */, cifs_sb->local_nls,
2864			      cifs_sb->mnt_cifs_flags &
2865				CIFS_MOUNT_MAP_SPECIAL_CHR);
2866
2867	if (rc == -EOPNOTSUPP || rc == -EINVAL)
2868		rc = SMBQueryInformation(xid, tcon, full_path, pfile_info,
2869				cifs_sb->local_nls, cifs_sb->mnt_cifs_flags &
2870				  CIFS_MOUNT_MAP_SPECIAL_CHR);
2871	kfree(pfile_info);
2872	return rc;
2873}
2874
2875static void
2876cleanup_volume_info_contents(struct smb_vol *volume_info)
2877{
2878	kfree(volume_info->username);
2879	kzfree(volume_info->password);
2880	kfree(volume_info->UNC);
2881	if (volume_info->UNCip != volume_info->UNC + 2)
2882		kfree(volume_info->UNCip);
2883	kfree(volume_info->domainname);
2884	kfree(volume_info->iocharset);
2885	kfree(volume_info->prepath);
2886}
2887
2888void
2889cifs_cleanup_volume_info(struct smb_vol *volume_info)
2890{
2891	if (!volume_info)
2892		return;
2893	cleanup_volume_info_contents(volume_info);
2894	kfree(volume_info);
2895}
2896
2897
2898#ifdef CONFIG_CIFS_DFS_UPCALL
2899/* build_path_to_root returns full path to root when
2900 * we do not have an exiting connection (tcon) */
2901static char *
2902build_unc_path_to_root(const struct smb_vol *vol,
2903		const struct cifs_sb_info *cifs_sb)
2904{
2905	char *full_path, *pos;
2906	unsigned int pplen = vol->prepath ? strlen(vol->prepath) : 0;
2907	unsigned int unc_len = strnlen(vol->UNC, MAX_TREE_SIZE + 1);
2908
2909	full_path = kmalloc(unc_len + pplen + 1, GFP_KERNEL);
2910	if (full_path == NULL)
2911		return ERR_PTR(-ENOMEM);
2912
2913	strncpy(full_path, vol->UNC, unc_len);
2914	pos = full_path + unc_len;
2915
2916	if (pplen) {
2917		strncpy(pos, vol->prepath, pplen);
2918		pos += pplen;
2919	}
2920
2921	*pos = '\0'; /* add trailing null */
2922	convert_delimiter(full_path, CIFS_DIR_SEP(cifs_sb));
2923	cFYI(1, "%s: full_path=%s", __func__, full_path);
2924	return full_path;
2925}
2926
2927/*
2928 * Perform a dfs referral query for a share and (optionally) prefix
2929 *
2930 * If a referral is found, cifs_sb->mountdata will be (re-)allocated
2931 * to a string containing updated options for the submount.  Otherwise it
2932 * will be left untouched.
2933 *
2934 * Returns the rc from get_dfs_path to the caller, which can be used to
2935 * determine whether there were referrals.
2936 */
2937static int
2938expand_dfs_referral(int xid, struct cifs_ses *pSesInfo,
2939		    struct smb_vol *volume_info, struct cifs_sb_info *cifs_sb,
2940		    int check_prefix)
2941{
2942	int rc;
2943	unsigned int num_referrals = 0;
2944	struct dfs_info3_param *referrals = NULL;
2945	char *full_path = NULL, *ref_path = NULL, *mdata = NULL;
2946
2947	full_path = build_unc_path_to_root(volume_info, cifs_sb);
2948	if (IS_ERR(full_path))
2949		return PTR_ERR(full_path);
2950
2951	/* For DFS paths, skip the first '\' of the UNC */
2952	ref_path = check_prefix ? full_path + 1 : volume_info->UNC + 1;
2953
2954	rc = get_dfs_path(xid, pSesInfo , ref_path, cifs_sb->local_nls,
2955			  &num_referrals, &referrals,
2956			  cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MAP_SPECIAL_CHR);
2957
2958	if (!rc && num_referrals > 0) {
2959		char *fake_devname = NULL;
2960
2961		mdata = cifs_compose_mount_options(cifs_sb->mountdata,
2962						   full_path + 1, referrals,
2963						   &fake_devname);
2964
2965		free_dfs_info_array(referrals, num_referrals);
2966
2967		if (IS_ERR(mdata)) {
2968			rc = PTR_ERR(mdata);
2969			mdata = NULL;
2970		} else {
2971			cleanup_volume_info_contents(volume_info);
2972			memset(volume_info, '\0', sizeof(*volume_info));
2973			rc = cifs_setup_volume_info(volume_info, mdata,
2974							fake_devname);
2975		}
2976		kfree(fake_devname);
2977		kfree(cifs_sb->mountdata);
2978		cifs_sb->mountdata = mdata;
2979	}
2980	kfree(full_path);
2981	return rc;
2982}
2983#endif
2984
2985static int
2986cifs_setup_volume_info(struct smb_vol *volume_info, char *mount_data,
2987			const char *devname)
2988{
 
 
 
 
 
 
 
 
 
 
 
 
2989	int rc = 0;
2990
2991	if (cifs_parse_mount_options(mount_data, devname, volume_info))
2992		return -EINVAL;
2993
2994	if (volume_info->nullauth) {
2995		cFYI(1, "null user");
2996		volume_info->username = kzalloc(1, GFP_KERNEL);
2997		if (volume_info->username == NULL)
2998			return -ENOMEM;
2999	} else if (volume_info->username) {
3000		/* BB fixme parse for domain name here */
3001		cFYI(1, "Username: %s", volume_info->username);
3002	} else {
3003		cifserror("No username specified");
3004	/* In userspace mount helper we can get user name from alternate
3005	   locations such as env variables and files on disk */
3006		return -EINVAL;
3007	}
 
3008
3009	/* this is needed for ASCII cp to Unicode converts */
3010	if (volume_info->iocharset == NULL) {
3011		/* load_nls_default cannot return null */
3012		volume_info->local_nls = load_nls_default();
3013	} else {
3014		volume_info->local_nls = load_nls(volume_info->iocharset);
3015		if (volume_info->local_nls == NULL) {
3016			cERROR(1, "CIFS mount error: iocharset %s not found",
3017				 volume_info->iocharset);
3018			return -ELIBACC;
3019		}
3020	}
3021
3022	return rc;
3023}
3024
3025struct smb_vol *
3026cifs_get_volume_info(char *mount_data, const char *devname)
3027{
3028	int rc;
3029	struct smb_vol *volume_info;
3030
3031	volume_info = kzalloc(sizeof(struct smb_vol), GFP_KERNEL);
3032	if (!volume_info)
3033		return ERR_PTR(-ENOMEM);
3034
3035	rc = cifs_setup_volume_info(volume_info, mount_data, devname);
3036	if (rc) {
3037		cifs_cleanup_volume_info(volume_info);
3038		volume_info = ERR_PTR(rc);
3039	}
3040
3041	return volume_info;
 
 
 
 
 
 
3042}
3043
3044int
3045cifs_mount(struct cifs_sb_info *cifs_sb, struct smb_vol *volume_info)
3046{
 
 
 
 
3047	int rc = 0;
3048	int xid;
3049	struct cifs_ses *pSesInfo;
3050	struct cifs_tcon *tcon;
3051	struct TCP_Server_Info *srvTcp;
3052	char   *full_path;
3053	struct tcon_link *tlink;
3054#ifdef CONFIG_CIFS_DFS_UPCALL
3055	int referral_walks_count = 0;
3056#endif
3057
3058	rc = bdi_setup_and_register(&cifs_sb->bdi, "cifs", BDI_CAP_MAP_COPY);
3059	if (rc)
3060		return rc;
3061
3062	cifs_sb->bdi.ra_pages = default_backing_dev_info.ra_pages;
3063
3064#ifdef CONFIG_CIFS_DFS_UPCALL
3065try_mount_again:
3066	/* cleanup activities if we're chasing a referral */
3067	if (referral_walks_count) {
3068		if (tcon)
3069			cifs_put_tcon(tcon);
3070		else if (pSesInfo)
3071			cifs_put_smb_ses(pSesInfo);
3072
3073		FreeXid(xid);
3074	}
3075#endif
3076	tcon = NULL;
3077	pSesInfo = NULL;
3078	srvTcp = NULL;
3079	full_path = NULL;
3080	tlink = NULL;
3081
3082	xid = GetXid();
3083
3084	/* get a reference to a tcp session */
3085	srvTcp = cifs_get_tcp_session(volume_info);
3086	if (IS_ERR(srvTcp)) {
3087		rc = PTR_ERR(srvTcp);
3088		bdi_destroy(&cifs_sb->bdi);
3089		goto out;
3090	}
3091
3092	/* get a reference to a SMB session */
3093	pSesInfo = cifs_get_smb_ses(srvTcp, volume_info);
3094	if (IS_ERR(pSesInfo)) {
3095		rc = PTR_ERR(pSesInfo);
3096		pSesInfo = NULL;
3097		goto mount_fail_check;
3098	}
3099
3100	/* search for existing tcon to this server share */
3101	tcon = cifs_get_tcon(pSesInfo, volume_info);
3102	if (IS_ERR(tcon)) {
3103		rc = PTR_ERR(tcon);
3104		tcon = NULL;
3105		goto remote_path_check;
3106	}
3107
 
 
 
 
 
3108	/* tell server which Unix caps we support */
3109	if (tcon->ses->capabilities & CAP_UNIX) {
3110		/* reset of caps checks mount to see if unix extensions
3111		   disabled for just this mount */
3112		reset_cifs_unix_caps(xid, tcon, cifs_sb, volume_info);
 
 
 
3113		if ((tcon->ses->server->tcpStatus == CifsNeedReconnect) &&
3114		    (le64_to_cpu(tcon->fsUnixInfo.Capability) &
3115		     CIFS_UNIX_TRANSPORT_ENCRYPTION_MANDATORY_CAP)) {
 
3116			rc = -EACCES;
3117			goto mount_fail_check;
3118		}
 
3119	} else
 
3120		tcon->unix_ext = 0; /* server does not support them */
3121
3122	/* do not care if following two calls succeed - informational */
3123	if (!tcon->ipc) {
3124		CIFSSMBQFSDeviceInfo(xid, tcon);
3125		CIFSSMBQFSAttributeInfo(xid, tcon);
3126	}
3127
3128	if ((tcon->unix_ext == 0) && (cifs_sb->rsize > (1024 * 127))) {
3129		cifs_sb->rsize = 1024 * 127;
3130		cFYI(DBG2, "no very large read support, rsize now 127K");
3131	}
3132	if (!(tcon->ses->capabilities & CAP_LARGE_READ_X))
3133		cifs_sb->rsize = min(cifs_sb->rsize,
3134			       (tcon->ses->server->maxBuf - MAX_CIFS_HDR_SIZE));
3135
3136	cifs_sb->wsize = cifs_negotiate_wsize(tcon, volume_info);
3137
3138remote_path_check:
3139#ifdef CONFIG_CIFS_DFS_UPCALL
3140	/*
3141	 * Perform an unconditional check for whether there are DFS
3142	 * referrals for this path without prefix, to provide support
3143	 * for DFS referrals from w2k8 servers which don't seem to respond
3144	 * with PATH_NOT_COVERED to requests that include the prefix.
3145	 * Chase the referral if found, otherwise continue normally.
3146	 */
3147	if (referral_walks_count == 0) {
3148		int refrc = expand_dfs_referral(xid, pSesInfo, volume_info,
3149						cifs_sb, false);
3150		if (!refrc) {
3151			referral_walks_count++;
3152			goto try_mount_again;
3153		}
3154	}
3155#endif
3156
3157	/* check if a whole path is not remote */
3158	if (!rc && tcon) {
3159		/* build_path_to_root works only when we have a valid tcon */
3160		full_path = cifs_build_path_to_root(volume_info, cifs_sb, tcon);
3161		if (full_path == NULL) {
3162			rc = -ENOMEM;
3163			goto mount_fail_check;
3164		}
3165		rc = is_path_accessible(xid, tcon, cifs_sb, full_path);
3166		if (rc != 0 && rc != -EREMOTE) {
3167			kfree(full_path);
3168			goto mount_fail_check;
3169		}
3170		kfree(full_path);
3171	}
3172
3173	/* get referral if needed */
3174	if (rc == -EREMOTE) {
3175#ifdef CONFIG_CIFS_DFS_UPCALL
3176		if (referral_walks_count > MAX_NESTED_LINKS) {
3177			/*
3178			 * BB: when we implement proper loop detection,
3179			 *     we will remove this check. But now we need it
3180			 *     to prevent an indefinite loop if 'DFS tree' is
3181			 *     misconfigured (i.e. has loops).
3182			 */
3183			rc = -ELOOP;
3184			goto mount_fail_check;
3185		}
3186
3187		rc = expand_dfs_referral(xid, pSesInfo, volume_info, cifs_sb,
3188					 true);
 
 
 
 
 
3189
3190		if (!rc) {
3191			referral_walks_count++;
3192			goto try_mount_again;
3193		}
3194		goto mount_fail_check;
3195#else /* No DFS support, return error on mount */
3196		rc = -EOPNOTSUPP;
3197#endif
3198	}
3199
3200	if (rc)
3201		goto mount_fail_check;
 
 
3202
3203	/* now, hang the tcon off of the superblock */
3204	tlink = kzalloc(sizeof *tlink, GFP_KERNEL);
3205	if (tlink == NULL) {
3206		rc = -ENOMEM;
3207		goto mount_fail_check;
3208	}
3209
3210	tlink->tl_uid = pSesInfo->linux_uid;
3211	tlink->tl_tcon = tcon;
3212	tlink->tl_time = jiffies;
3213	set_bit(TCON_LINK_MASTER, &tlink->tl_flags);
3214	set_bit(TCON_LINK_IN_TREE, &tlink->tl_flags);
3215
3216	cifs_sb->master_tlink = tlink;
3217	spin_lock(&cifs_sb->tlink_tree_lock);
3218	tlink_rb_insert(&cifs_sb->tlink_tree, tlink);
3219	spin_unlock(&cifs_sb->tlink_tree_lock);
3220
3221	queue_delayed_work(system_nrt_wq, &cifs_sb->prune_tlinks,
3222				TLINK_IDLE_EXPIRE);
 
 
3223
3224mount_fail_check:
3225	/* on error free sesinfo and tcon struct if needed */
3226	if (rc) {
3227		/* If find_unc succeeded then rc == 0 so we can not end */
3228		/* up accidentally freeing someone elses tcon struct */
3229		if (tcon)
3230			cifs_put_tcon(tcon);
3231		else if (pSesInfo)
3232			cifs_put_smb_ses(pSesInfo);
3233		else
3234			cifs_put_tcp_session(srvTcp);
3235		bdi_destroy(&cifs_sb->bdi);
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3236	}
3237
3238out:
3239	FreeXid(xid);
3240	return rc;
3241}
3242
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3243/*
3244 * Issue a TREE_CONNECT request. Note that for IPC$ shares, that the tcon
3245 * pointer may be NULL.
3246 */
3247int
3248CIFSTCon(unsigned int xid, struct cifs_ses *ses,
3249	 const char *tree, struct cifs_tcon *tcon,
3250	 const struct nls_table *nls_codepage)
3251{
3252	struct smb_hdr *smb_buffer;
3253	struct smb_hdr *smb_buffer_response;
3254	TCONX_REQ *pSMB;
3255	TCONX_RSP *pSMBr;
3256	unsigned char *bcc_ptr;
3257	int rc = 0;
3258	int length;
3259	__u16 bytes_left, count;
3260
3261	if (ses == NULL)
3262		return -EIO;
3263
3264	smb_buffer = cifs_buf_get();
3265	if (smb_buffer == NULL)
3266		return -ENOMEM;
3267
3268	smb_buffer_response = smb_buffer;
3269
3270	header_assemble(smb_buffer, SMB_COM_TREE_CONNECT_ANDX,
3271			NULL /*no tid */ , 4 /*wct */ );
3272
3273	smb_buffer->Mid = GetNextMid(ses->server);
3274	smb_buffer->Uid = ses->Suid;
3275	pSMB = (TCONX_REQ *) smb_buffer;
3276	pSMBr = (TCONX_RSP *) smb_buffer_response;
3277
3278	pSMB->AndXCommand = 0xFF;
3279	pSMB->Flags = cpu_to_le16(TCON_EXTENDED_SECINFO);
3280	bcc_ptr = &pSMB->Password[0];
3281	if (!tcon || (ses->server->sec_mode & SECMODE_USER)) {
3282		pSMB->PasswordLength = cpu_to_le16(1);	/* minimum */
3283		*bcc_ptr = 0; /* password is null byte */
3284		bcc_ptr++;              /* skip password */
3285		/* already aligned so no need to do it below */
3286	} else {
3287		pSMB->PasswordLength = cpu_to_le16(CIFS_AUTH_RESP_SIZE);
3288		/* BB FIXME add code to fail this if NTLMv2 or Kerberos
3289		   specified as required (when that support is added to
3290		   the vfs in the future) as only NTLM or the much
3291		   weaker LANMAN (which we do not send by default) is accepted
3292		   by Samba (not sure whether other servers allow
3293		   NTLMv2 password here) */
3294#ifdef CONFIG_CIFS_WEAK_PW_HASH
3295		if ((global_secflags & CIFSSEC_MAY_LANMAN) &&
3296		    (ses->server->secType == LANMAN))
3297			calc_lanman_hash(tcon->password, ses->server->cryptkey,
3298					 ses->server->sec_mode &
3299					    SECMODE_PW_ENCRYPT ? true : false,
3300					 bcc_ptr);
3301		else
3302#endif /* CIFS_WEAK_PW_HASH */
3303		rc = SMBNTencrypt(tcon->password, ses->server->cryptkey,
3304					bcc_ptr);
3305
3306		bcc_ptr += CIFS_AUTH_RESP_SIZE;
3307		if (ses->capabilities & CAP_UNICODE) {
3308			/* must align unicode strings */
3309			*bcc_ptr = 0; /* null byte password */
3310			bcc_ptr++;
3311		}
3312	}
3313
3314	if (ses->server->sec_mode &
3315			(SECMODE_SIGN_REQUIRED | SECMODE_SIGN_ENABLED))
3316		smb_buffer->Flags2 |= SMBFLG2_SECURITY_SIGNATURE;
3317
3318	if (ses->capabilities & CAP_STATUS32) {
3319		smb_buffer->Flags2 |= SMBFLG2_ERR_STATUS;
3320	}
3321	if (ses->capabilities & CAP_DFS) {
3322		smb_buffer->Flags2 |= SMBFLG2_DFS;
3323	}
3324	if (ses->capabilities & CAP_UNICODE) {
3325		smb_buffer->Flags2 |= SMBFLG2_UNICODE;
3326		length =
3327		    cifs_strtoUCS((__le16 *) bcc_ptr, tree,
3328			6 /* max utf8 char length in bytes */ *
3329			(/* server len*/ + 256 /* share len */), nls_codepage);
3330		bcc_ptr += 2 * length;	/* convert num 16 bit words to bytes */
3331		bcc_ptr += 2;	/* skip trailing null */
3332	} else {		/* ASCII */
3333		strcpy(bcc_ptr, tree);
3334		bcc_ptr += strlen(tree) + 1;
3335	}
3336	strcpy(bcc_ptr, "?????");
3337	bcc_ptr += strlen("?????");
3338	bcc_ptr += 1;
3339	count = bcc_ptr - &pSMB->Password[0];
3340	pSMB->hdr.smb_buf_length = cpu_to_be32(be32_to_cpu(
3341					pSMB->hdr.smb_buf_length) + count);
3342	pSMB->ByteCount = cpu_to_le16(count);
3343
3344	rc = SendReceive(xid, ses, smb_buffer, smb_buffer_response, &length,
3345			 0);
3346
3347	/* above now done in SendReceive */
3348	if ((rc == 0) && (tcon != NULL)) {
3349		bool is_unicode;
3350
3351		tcon->tidStatus = CifsGood;
3352		tcon->need_reconnect = false;
3353		tcon->tid = smb_buffer_response->Tid;
3354		bcc_ptr = pByteArea(smb_buffer_response);
3355		bytes_left = get_bcc(smb_buffer_response);
3356		length = strnlen(bcc_ptr, bytes_left - 2);
3357		if (smb_buffer->Flags2 & SMBFLG2_UNICODE)
3358			is_unicode = true;
3359		else
3360			is_unicode = false;
3361
3362
3363		/* skip service field (NB: this field is always ASCII) */
3364		if (length == 3) {
3365			if ((bcc_ptr[0] == 'I') && (bcc_ptr[1] == 'P') &&
3366			    (bcc_ptr[2] == 'C')) {
3367				cFYI(1, "IPC connection");
3368				tcon->ipc = 1;
 
3369			}
3370		} else if (length == 2) {
3371			if ((bcc_ptr[0] == 'A') && (bcc_ptr[1] == ':')) {
3372				/* the most common case */
3373				cFYI(1, "disk share connection");
3374			}
3375		}
3376		bcc_ptr += length + 1;
3377		bytes_left -= (length + 1);
3378		strncpy(tcon->treeName, tree, MAX_TREE_SIZE);
3379
3380		/* mostly informational -- no need to fail on error here */
3381		kfree(tcon->nativeFileSystem);
3382		tcon->nativeFileSystem = cifs_strndup_from_ucs(bcc_ptr,
3383						      bytes_left, is_unicode,
3384						      nls_codepage);
3385
3386		cFYI(1, "nativeFileSystem=%s", tcon->nativeFileSystem);
3387
3388		if ((smb_buffer_response->WordCount == 3) ||
3389			 (smb_buffer_response->WordCount == 7))
3390			/* field is in same location */
3391			tcon->Flags = le16_to_cpu(pSMBr->OptionalSupport);
3392		else
3393			tcon->Flags = 0;
3394		cFYI(1, "Tcon flags: 0x%x ", tcon->Flags);
3395	} else if ((rc == 0) && tcon == NULL) {
3396		/* all we need to save for IPC$ connection */
3397		ses->ipc_tid = smb_buffer_response->Tid;
3398	}
3399
3400	cifs_buf_release(smb_buffer);
3401	return rc;
3402}
3403
 
 
 
 
 
 
 
 
 
3404void
3405cifs_umount(struct cifs_sb_info *cifs_sb)
3406{
3407	struct rb_root *root = &cifs_sb->tlink_tree;
3408	struct rb_node *node;
3409	struct tcon_link *tlink;
3410
3411	cancel_delayed_work_sync(&cifs_sb->prune_tlinks);
3412
3413	spin_lock(&cifs_sb->tlink_tree_lock);
3414	while ((node = rb_first(root))) {
3415		tlink = rb_entry(node, struct tcon_link, tl_rbnode);
3416		cifs_get_tlink(tlink);
3417		clear_bit(TCON_LINK_IN_TREE, &tlink->tl_flags);
3418		rb_erase(node, root);
3419
3420		spin_unlock(&cifs_sb->tlink_tree_lock);
3421		cifs_put_tlink(tlink);
3422		spin_lock(&cifs_sb->tlink_tree_lock);
3423	}
3424	spin_unlock(&cifs_sb->tlink_tree_lock);
3425
3426	bdi_destroy(&cifs_sb->bdi);
3427	kfree(cifs_sb->mountdata);
3428	unload_nls(cifs_sb->local_nls);
3429	kfree(cifs_sb);
 
3430}
3431
3432int cifs_negotiate_protocol(unsigned int xid, struct cifs_ses *ses)
 
 
3433{
3434	int rc = 0;
3435	struct TCP_Server_Info *server = ses->server;
 
 
3436
3437	/* only send once per connect */
3438	if (server->maxBuf != 0)
 
 
 
3439		return 0;
3440
3441	rc = CIFSSMBNegotiate(xid, ses);
3442	if (rc == -EAGAIN) {
3443		/* retry only once on 1st time connection */
3444		rc = CIFSSMBNegotiate(xid, ses);
3445		if (rc == -EAGAIN)
3446			rc = -EHOSTDOWN;
3447	}
 
 
 
 
3448	if (rc == 0) {
3449		spin_lock(&GlobalMid_Lock);
3450		if (server->tcpStatus == CifsNeedNegotiate)
3451			server->tcpStatus = CifsGood;
3452		else
3453			rc = -EHOSTDOWN;
3454		spin_unlock(&GlobalMid_Lock);
3455
 
 
 
 
3456	}
3457
3458	return rc;
3459}
3460
3461
3462int cifs_setup_session(unsigned int xid, struct cifs_ses *ses,
3463			struct nls_table *nls_info)
 
3464{
3465	int rc = 0;
3466	struct TCP_Server_Info *server = ses->server;
 
 
3467
3468	ses->flags = 0;
3469	ses->capabilities = server->capabilities;
3470	if (linuxExtEnabled == 0)
3471		ses->capabilities &= (~CAP_UNIX);
 
3472
3473	cFYI(1, "Security Mode: 0x%x Capabilities: 0x%x TimeAdjust: %d",
3474		 server->sec_mode, server->capabilities, server->timeAdj);
 
 
 
 
3475
3476	rc = CIFS_SessSetup(xid, ses, nls_info);
3477	if (rc) {
3478		cERROR(1, "Send error in SessSetup = %d", rc);
3479	} else {
3480		mutex_lock(&ses->server->srv_mutex);
3481		if (!server->session_estab) {
3482			server->session_key.response = ses->auth_key.response;
3483			server->session_key.len = ses->auth_key.len;
3484			server->sequence_number = 0x2;
3485			server->session_estab = true;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3486			ses->auth_key.response = NULL;
 
3487		}
3488		mutex_unlock(&server->srv_mutex);
3489
3490		cFYI(1, "CIFS Session Established successfully");
3491		spin_lock(&GlobalMid_Lock);
3492		ses->status = CifsGood;
3493		ses->need_reconnect = false;
3494		spin_unlock(&GlobalMid_Lock);
3495	}
3496
3497	kfree(ses->auth_key.response);
3498	ses->auth_key.response = NULL;
3499	ses->auth_key.len = 0;
3500	kfree(ses->ntlmssp);
3501	ses->ntlmssp = NULL;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3502
3503	return rc;
3504}
3505
 
 
 
 
 
 
 
 
 
 
 
 
3506static struct cifs_tcon *
3507cifs_construct_tcon(struct cifs_sb_info *cifs_sb, uid_t fsuid)
3508{
 
3509	struct cifs_tcon *master_tcon = cifs_sb_master_tcon(cifs_sb);
3510	struct cifs_ses *ses;
3511	struct cifs_tcon *tcon = NULL;
3512	struct smb_vol *vol_info;
3513	char username[28]; /* big enough for "krb50x" + hex of ULONG_MAX 6+16 */
3514			   /* We used to have this as MAX_USERNAME which is   */
3515			   /* way too big now (256 instead of 32) */
3516
3517	vol_info = kzalloc(sizeof(*vol_info), GFP_KERNEL);
3518	if (vol_info == NULL) {
3519		tcon = ERR_PTR(-ENOMEM);
3520		goto out;
3521	}
3522
3523	snprintf(username, sizeof(username), "krb50x%x", fsuid);
3524	vol_info->username = username;
3525	vol_info->local_nls = cifs_sb->local_nls;
3526	vol_info->linux_uid = fsuid;
3527	vol_info->cred_uid = fsuid;
3528	vol_info->UNC = master_tcon->treeName;
3529	vol_info->retry = master_tcon->retry;
3530	vol_info->nocase = master_tcon->nocase;
3531	vol_info->local_lease = master_tcon->local_lease;
3532	vol_info->no_linux_ext = !master_tcon->unix_ext;
 
 
 
 
 
 
 
 
 
 
 
 
3533
3534	/* FIXME: allow for other secFlg settings */
3535	vol_info->secFlg = CIFSSEC_MUST_KRB5;
 
 
 
3536
3537	/* get a reference for the same TCP session */
3538	spin_lock(&cifs_tcp_ses_lock);
3539	++master_tcon->ses->server->srv_count;
3540	spin_unlock(&cifs_tcp_ses_lock);
3541
3542	ses = cifs_get_smb_ses(master_tcon->ses->server, vol_info);
3543	if (IS_ERR(ses)) {
3544		tcon = (struct cifs_tcon *)ses;
3545		cifs_put_tcp_session(master_tcon->ses->server);
3546		goto out;
3547	}
3548
3549	tcon = cifs_get_tcon(ses, vol_info);
3550	if (IS_ERR(tcon)) {
3551		cifs_put_smb_ses(ses);
3552		goto out;
3553	}
3554
3555	if (ses->capabilities & CAP_UNIX)
3556		reset_cifs_unix_caps(0, tcon, NULL, vol_info);
 
 
 
3557out:
3558	kfree(vol_info);
 
 
3559
3560	return tcon;
3561}
3562
3563struct cifs_tcon *
3564cifs_sb_master_tcon(struct cifs_sb_info *cifs_sb)
3565{
3566	return tlink_tcon(cifs_sb_master_tlink(cifs_sb));
3567}
3568
3569static int
3570cifs_sb_tcon_pending_wait(void *unused)
3571{
3572	schedule();
3573	return signal_pending(current) ? -ERESTARTSYS : 0;
3574}
3575
3576/* find and return a tlink with given uid */
3577static struct tcon_link *
3578tlink_rb_search(struct rb_root *root, uid_t uid)
3579{
3580	struct rb_node *node = root->rb_node;
3581	struct tcon_link *tlink;
3582
3583	while (node) {
3584		tlink = rb_entry(node, struct tcon_link, tl_rbnode);
3585
3586		if (tlink->tl_uid > uid)
3587			node = node->rb_left;
3588		else if (tlink->tl_uid < uid)
3589			node = node->rb_right;
3590		else
3591			return tlink;
3592	}
3593	return NULL;
3594}
3595
3596/* insert a tcon_link into the tree */
3597static void
3598tlink_rb_insert(struct rb_root *root, struct tcon_link *new_tlink)
3599{
3600	struct rb_node **new = &(root->rb_node), *parent = NULL;
3601	struct tcon_link *tlink;
3602
3603	while (*new) {
3604		tlink = rb_entry(*new, struct tcon_link, tl_rbnode);
3605		parent = *new;
3606
3607		if (tlink->tl_uid > new_tlink->tl_uid)
3608			new = &((*new)->rb_left);
3609		else
3610			new = &((*new)->rb_right);
3611	}
3612
3613	rb_link_node(&new_tlink->tl_rbnode, parent, new);
3614	rb_insert_color(&new_tlink->tl_rbnode, root);
3615}
3616
3617/*
3618 * Find or construct an appropriate tcon given a cifs_sb and the fsuid of the
3619 * current task.
3620 *
3621 * If the superblock doesn't refer to a multiuser mount, then just return
3622 * the master tcon for the mount.
3623 *
3624 * First, search the rbtree for an existing tcon for this fsuid. If one
3625 * exists, then check to see if it's pending construction. If it is then wait
3626 * for construction to complete. Once it's no longer pending, check to see if
3627 * it failed and either return an error or retry construction, depending on
3628 * the timeout.
3629 *
3630 * If one doesn't exist then insert a new tcon_link struct into the tree and
3631 * try to construct a new one.
3632 */
3633struct tcon_link *
3634cifs_sb_tlink(struct cifs_sb_info *cifs_sb)
3635{
3636	int ret;
3637	uid_t fsuid = current_fsuid();
3638	struct tcon_link *tlink, *newtlink;
3639
3640	if (!(cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MULTIUSER))
3641		return cifs_get_tlink(cifs_sb_master_tlink(cifs_sb));
3642
3643	spin_lock(&cifs_sb->tlink_tree_lock);
3644	tlink = tlink_rb_search(&cifs_sb->tlink_tree, fsuid);
3645	if (tlink)
3646		cifs_get_tlink(tlink);
3647	spin_unlock(&cifs_sb->tlink_tree_lock);
3648
3649	if (tlink == NULL) {
3650		newtlink = kzalloc(sizeof(*tlink), GFP_KERNEL);
3651		if (newtlink == NULL)
3652			return ERR_PTR(-ENOMEM);
3653		newtlink->tl_uid = fsuid;
3654		newtlink->tl_tcon = ERR_PTR(-EACCES);
3655		set_bit(TCON_LINK_PENDING, &newtlink->tl_flags);
3656		set_bit(TCON_LINK_IN_TREE, &newtlink->tl_flags);
3657		cifs_get_tlink(newtlink);
3658
3659		spin_lock(&cifs_sb->tlink_tree_lock);
3660		/* was one inserted after previous search? */
3661		tlink = tlink_rb_search(&cifs_sb->tlink_tree, fsuid);
3662		if (tlink) {
3663			cifs_get_tlink(tlink);
3664			spin_unlock(&cifs_sb->tlink_tree_lock);
3665			kfree(newtlink);
3666			goto wait_for_construction;
3667		}
3668		tlink = newtlink;
3669		tlink_rb_insert(&cifs_sb->tlink_tree, tlink);
3670		spin_unlock(&cifs_sb->tlink_tree_lock);
3671	} else {
3672wait_for_construction:
3673		ret = wait_on_bit(&tlink->tl_flags, TCON_LINK_PENDING,
3674				  cifs_sb_tcon_pending_wait,
3675				  TASK_INTERRUPTIBLE);
3676		if (ret) {
3677			cifs_put_tlink(tlink);
3678			return ERR_PTR(ret);
3679		}
3680
3681		/* if it's good, return it */
3682		if (!IS_ERR(tlink->tl_tcon))
3683			return tlink;
3684
3685		/* return error if we tried this already recently */
3686		if (time_before(jiffies, tlink->tl_time + TLINK_ERROR_EXPIRE)) {
3687			cifs_put_tlink(tlink);
3688			return ERR_PTR(-EACCES);
3689		}
3690
3691		if (test_and_set_bit(TCON_LINK_PENDING, &tlink->tl_flags))
3692			goto wait_for_construction;
3693	}
3694
3695	tlink->tl_tcon = cifs_construct_tcon(cifs_sb, fsuid);
3696	clear_bit(TCON_LINK_PENDING, &tlink->tl_flags);
3697	wake_up_bit(&tlink->tl_flags, TCON_LINK_PENDING);
3698
3699	if (IS_ERR(tlink->tl_tcon)) {
3700		cifs_put_tlink(tlink);
3701		return ERR_PTR(-EACCES);
3702	}
3703
3704	return tlink;
3705}
3706
3707/*
3708 * periodic workqueue job that scans tcon_tree for a superblock and closes
3709 * out tcons.
3710 */
3711static void
3712cifs_prune_tlinks(struct work_struct *work)
3713{
3714	struct cifs_sb_info *cifs_sb = container_of(work, struct cifs_sb_info,
3715						    prune_tlinks.work);
3716	struct rb_root *root = &cifs_sb->tlink_tree;
3717	struct rb_node *node = rb_first(root);
3718	struct rb_node *tmp;
3719	struct tcon_link *tlink;
3720
3721	/*
3722	 * Because we drop the spinlock in the loop in order to put the tlink
3723	 * it's not guarded against removal of links from the tree. The only
3724	 * places that remove entries from the tree are this function and
3725	 * umounts. Because this function is non-reentrant and is canceled
3726	 * before umount can proceed, this is safe.
3727	 */
3728	spin_lock(&cifs_sb->tlink_tree_lock);
3729	node = rb_first(root);
3730	while (node != NULL) {
3731		tmp = node;
3732		node = rb_next(tmp);
3733		tlink = rb_entry(tmp, struct tcon_link, tl_rbnode);
3734
3735		if (test_bit(TCON_LINK_MASTER, &tlink->tl_flags) ||
3736		    atomic_read(&tlink->tl_count) != 0 ||
3737		    time_after(tlink->tl_time + TLINK_IDLE_EXPIRE, jiffies))
3738			continue;
3739
3740		cifs_get_tlink(tlink);
3741		clear_bit(TCON_LINK_IN_TREE, &tlink->tl_flags);
3742		rb_erase(tmp, root);
3743
3744		spin_unlock(&cifs_sb->tlink_tree_lock);
3745		cifs_put_tlink(tlink);
3746		spin_lock(&cifs_sb->tlink_tree_lock);
3747	}
3748	spin_unlock(&cifs_sb->tlink_tree_lock);
3749
3750	queue_delayed_work(system_nrt_wq, &cifs_sb->prune_tlinks,
3751				TLINK_IDLE_EXPIRE);
3752}
v6.2
   1// SPDX-License-Identifier: LGPL-2.1
   2/*
 
   3 *
   4 *   Copyright (C) International Business Machines  Corp., 2002,2011
   5 *   Author(s): Steve French (sfrench@us.ibm.com)
   6 *
 
 
 
 
 
 
 
 
 
 
 
 
 
   7 */
   8#include <linux/fs.h>
   9#include <linux/net.h>
  10#include <linux/string.h>
  11#include <linux/sched/mm.h>
  12#include <linux/sched/signal.h>
  13#include <linux/list.h>
  14#include <linux/wait.h>
  15#include <linux/slab.h>
  16#include <linux/pagemap.h>
  17#include <linux/ctype.h>
  18#include <linux/utsname.h>
  19#include <linux/mempool.h>
  20#include <linux/delay.h>
  21#include <linux/completion.h>
  22#include <linux/kthread.h>
  23#include <linux/pagevec.h>
  24#include <linux/freezer.h>
  25#include <linux/namei.h>
  26#include <linux/uuid.h>
  27#include <linux/uaccess.h>
  28#include <asm/processor.h>
  29#include <linux/inet.h>
  30#include <linux/module.h>
  31#include <keys/user-type.h>
  32#include <net/ipv6.h>
  33#include <linux/parser.h>
  34#include <linux/bvec.h>
  35#include "cifspdu.h"
  36#include "cifsglob.h"
  37#include "cifsproto.h"
  38#include "cifs_unicode.h"
  39#include "cifs_debug.h"
  40#include "cifs_fs_sb.h"
  41#include "ntlmssp.h"
  42#include "nterr.h"
  43#include "rfc1002pdu.h"
  44#include "fscache.h"
  45#include "smb2proto.h"
  46#include "smbdirect.h"
  47#include "dns_resolve.h"
  48#ifdef CONFIG_CIFS_DFS_UPCALL
  49#include "dfs.h"
  50#include "dfs_cache.h"
  51#endif
  52#include "fs_context.h"
  53#include "cifs_swn.h"
  54
  55extern mempool_t *cifs_req_poolp;
  56extern bool disable_legacy_dialects;
  57
  58/* FIXME: should these be tunable? */
  59#define TLINK_ERROR_EXPIRE	(1 * HZ)
  60#define TLINK_IDLE_EXPIRE	(600 * HZ)
  61
  62/* Drop the connection to not overload the server */
  63#define NUM_STATUS_IO_TIMEOUT   5
  64
  65static int ip_connect(struct TCP_Server_Info *server);
  66static int generic_ip_connect(struct TCP_Server_Info *server);
  67static void tlink_rb_insert(struct rb_root *root, struct tcon_link *new_tlink);
  68static void cifs_prune_tlinks(struct work_struct *work);
 
 
  69
  70/*
  71 * Resolve hostname and set ip addr in tcp ses. Useful for hostnames that may
  72 * get their ip addresses changed at some point.
  73 *
  74 * This should be called with server->srv_mutex held.
 
 
 
  75 */
  76static int reconn_set_ipaddr_from_hostname(struct TCP_Server_Info *server)
 
  77{
  78	int rc;
  79	int len;
  80	char *unc;
  81	struct sockaddr_storage ss;
  82	time64_t expiry, now;
  83	unsigned long ttl = SMB_DNS_RESOLVE_INTERVAL_DEFAULT;
  84
  85	if (!server->hostname)
  86		return -EINVAL;
  87
  88	/* if server hostname isn't populated, there's nothing to do here */
  89	if (server->hostname[0] == '\0')
  90		return 0;
  91
  92	len = strlen(server->hostname) + 3;
  93
  94	unc = kmalloc(len, GFP_KERNEL);
  95	if (!unc) {
  96		cifs_dbg(FYI, "%s: failed to create UNC path\n", __func__);
  97		return -ENOMEM;
  98	}
  99	scnprintf(unc, len, "\\\\%s", server->hostname);
 100
 101	spin_lock(&server->srv_lock);
 102	ss = server->dstaddr;
 103	spin_unlock(&server->srv_lock);
 104
 105	rc = dns_resolve_server_name_to_ip(unc, (struct sockaddr *)&ss, &expiry);
 106	kfree(unc);
 107
 108	if (rc < 0) {
 109		cifs_dbg(FYI, "%s: failed to resolve server part of %s to IP: %d\n",
 110			 __func__, server->hostname, rc);
 111		goto requeue_resolve;
 112	}
 113
 114	spin_lock(&server->srv_lock);
 115	memcpy(&server->dstaddr, &ss, sizeof(server->dstaddr));
 116	spin_unlock(&server->srv_lock);
 117
 118	now = ktime_get_real_seconds();
 119	if (expiry && expiry > now)
 120		/* To make sure we don't use the cached entry, retry 1s */
 121		ttl = max_t(unsigned long, expiry - now, SMB_DNS_RESOLVE_INTERVAL_MIN) + 1;
 122
 123requeue_resolve:
 124	cifs_dbg(FYI, "%s: next dns resolution scheduled for %lu seconds in the future\n",
 125		 __func__, ttl);
 126	mod_delayed_work(cifsiod_wq, &server->resolve, (ttl * HZ));
 127
 128	return rc;
 129}
 130
 131static void smb2_query_server_interfaces(struct work_struct *work)
 132{
 133	int rc;
 134	struct cifs_tcon *tcon = container_of(work,
 135					struct cifs_tcon,
 136					query_interfaces.work);
 137
 138	/*
 139	 * query server network interfaces, in case they change
 140	 */
 141	rc = SMB3_request_interfaces(0, tcon, false);
 142	if (rc) {
 143		cifs_dbg(FYI, "%s: failed to query server interfaces: %d\n",
 144				__func__, rc);
 145	}
 146
 147	queue_delayed_work(cifsiod_wq, &tcon->query_interfaces,
 148			   (SMB_INTERFACE_POLL_INTERVAL * HZ));
 149}
 150
 151static void cifs_resolve_server(struct work_struct *work)
 152{
 153	int rc;
 154	struct TCP_Server_Info *server = container_of(work,
 155					struct TCP_Server_Info, resolve.work);
 156
 157	cifs_server_lock(server);
 158
 159	/*
 160	 * Resolve the hostname again to make sure that IP address is up-to-date.
 161	 */
 162	rc = reconn_set_ipaddr_from_hostname(server);
 163	if (rc) {
 164		cifs_dbg(FYI, "%s: failed to resolve hostname: %d\n",
 165				__func__, rc);
 166	}
 167
 168	cifs_server_unlock(server);
 169}
 170
 171/*
 172 * Update the tcpStatus for the server.
 173 * This is used to signal the cifsd thread to call cifs_reconnect
 174 * ONLY cifsd thread should call cifs_reconnect. For any other
 175 * thread, use this function
 176 *
 177 * @server: the tcp ses for which reconnect is needed
 178 * @all_channels: if this needs to be done for all channels
 179 */
 180void
 181cifs_signal_cifsd_for_reconnect(struct TCP_Server_Info *server,
 182				bool all_channels)
 183{
 184	struct TCP_Server_Info *pserver;
 185	struct cifs_ses *ses;
 186	int i;
 187
 188	/* If server is a channel, select the primary channel */
 189	pserver = CIFS_SERVER_IS_CHAN(server) ? server->primary_server : server;
 190
 191	spin_lock(&pserver->srv_lock);
 192	if (!all_channels) {
 193		pserver->tcpStatus = CifsNeedReconnect;
 194		spin_unlock(&pserver->srv_lock);
 195		return;
 196	}
 197	spin_unlock(&pserver->srv_lock);
 198
 199	spin_lock(&cifs_tcp_ses_lock);
 200	list_for_each_entry(ses, &pserver->smb_ses_list, smb_ses_list) {
 201		spin_lock(&ses->chan_lock);
 202		for (i = 0; i < ses->chan_count; i++) {
 203			spin_lock(&ses->chans[i].server->srv_lock);
 204			ses->chans[i].server->tcpStatus = CifsNeedReconnect;
 205			spin_unlock(&ses->chans[i].server->srv_lock);
 206		}
 207		spin_unlock(&ses->chan_lock);
 208	}
 209	spin_unlock(&cifs_tcp_ses_lock);
 210}
 211
 212/*
 213 * Mark all sessions and tcons for reconnect.
 214 * IMPORTANT: make sure that this gets called only from
 215 * cifsd thread. For any other thread, use
 216 * cifs_signal_cifsd_for_reconnect
 217 *
 218 * @server: the tcp ses for which reconnect is needed
 219 * @server needs to be previously set to CifsNeedReconnect.
 220 * @mark_smb_session: whether even sessions need to be marked
 221 */
 222void
 223cifs_mark_tcp_ses_conns_for_reconnect(struct TCP_Server_Info *server,
 224				      bool mark_smb_session)
 225{
 226	struct TCP_Server_Info *pserver;
 227	struct cifs_ses *ses, *nses;
 228	struct cifs_tcon *tcon;
 
 
 229
 230	/*
 231	 * before reconnecting the tcp session, mark the smb session (uid) and the tid bad so they
 232	 * are not used until reconnected.
 233	 */
 234	cifs_dbg(FYI, "%s: marking necessary sessions and tcons for reconnect\n", __func__);
 235
 236	/* If server is a channel, select the primary channel */
 237	pserver = CIFS_SERVER_IS_CHAN(server) ? server->primary_server : server;
 
 
 238
 
 239
 
 
 
 240	spin_lock(&cifs_tcp_ses_lock);
 241	list_for_each_entry_safe(ses, nses, &pserver->smb_ses_list, smb_ses_list) {
 242		/* check if iface is still active */
 243		if (!cifs_chan_is_iface_active(ses, server))
 244			cifs_chan_update_iface(ses, server);
 245
 246		spin_lock(&ses->chan_lock);
 247		if (!mark_smb_session && cifs_chan_needs_reconnect(ses, server))
 248			goto next_session;
 249
 250		if (mark_smb_session)
 251			CIFS_SET_ALL_CHANS_NEED_RECONNECT(ses);
 252		else
 253			cifs_chan_set_need_reconnect(ses, server);
 254
 255		/* If all channels need reconnect, then tcon needs reconnect */
 256		if (!mark_smb_session && !CIFS_ALL_CHANS_NEED_RECONNECT(ses))
 257			goto next_session;
 258
 259		ses->ses_status = SES_NEED_RECON;
 260
 261		list_for_each_entry(tcon, &ses->tcon_list, tcon_list) {
 262			tcon->need_reconnect = true;
 263			tcon->status = TID_NEED_RECON;
 264		}
 265		if (ses->tcon_ipc) {
 266			ses->tcon_ipc->need_reconnect = true;
 267			ses->tcon_ipc->status = TID_NEED_RECON;
 268		}
 269
 270next_session:
 271		spin_unlock(&ses->chan_lock);
 272	}
 273	spin_unlock(&cifs_tcp_ses_lock);
 274}
 275
 276static void
 277cifs_abort_connection(struct TCP_Server_Info *server)
 278{
 279	struct mid_q_entry *mid, *nmid;
 280	struct list_head retry_list;
 281
 282	server->maxBuf = 0;
 283	server->max_read = 0;
 284
 285	/* do not want to be sending data on a socket we are freeing */
 286	cifs_dbg(FYI, "%s: tearing down socket\n", __func__);
 287	cifs_server_lock(server);
 288	if (server->ssocket) {
 289		cifs_dbg(FYI, "State: 0x%x Flags: 0x%lx\n", server->ssocket->state,
 290			 server->ssocket->flags);
 291		kernel_sock_shutdown(server->ssocket, SHUT_WR);
 292		cifs_dbg(FYI, "Post shutdown state: 0x%x Flags: 0x%lx\n", server->ssocket->state,
 293			 server->ssocket->flags);
 
 294		sock_release(server->ssocket);
 295		server->ssocket = NULL;
 296	}
 297	server->sequence_number = 0;
 298	server->session_estab = false;
 299	kfree_sensitive(server->session_key.response);
 300	server->session_key.response = NULL;
 301	server->session_key.len = 0;
 302	server->lstrp = jiffies;
 
 303
 304	/* mark submitted MIDs for retry and issue callback */
 305	INIT_LIST_HEAD(&retry_list);
 306	cifs_dbg(FYI, "%s: moving mids to private list\n", __func__);
 307	spin_lock(&server->mid_lock);
 308	list_for_each_entry_safe(mid, nmid, &server->pending_mid_q, qhead) {
 309		kref_get(&mid->refcount);
 310		if (mid->mid_state == MID_REQUEST_SUBMITTED)
 311			mid->mid_state = MID_RETRY_NEEDED;
 312		list_move(&mid->qhead, &retry_list);
 313		mid->mid_flags |= MID_DELETED;
 
 
 
 
 
 
 
 314	}
 315	spin_unlock(&server->mid_lock);
 316	cifs_server_unlock(server);
 317
 318	cifs_dbg(FYI, "%s: issuing mid callbacks\n", __func__);
 319	list_for_each_entry_safe(mid, nmid, &retry_list, qhead) {
 320		list_del_init(&mid->qhead);
 321		mid->callback(mid);
 322		release_mid(mid);
 323	}
 324
 325	if (cifs_rdma_enabled(server)) {
 326		cifs_server_lock(server);
 327		smbd_destroy(server);
 328		cifs_server_unlock(server);
 329	}
 330}
 331
 332static bool cifs_tcp_ses_needs_reconnect(struct TCP_Server_Info *server, int num_targets)
 333{
 334	spin_lock(&server->srv_lock);
 335	server->nr_targets = num_targets;
 336	if (server->tcpStatus == CifsExiting) {
 337		/* the demux thread will exit normally next time through the loop */
 338		spin_unlock(&server->srv_lock);
 339		wake_up(&server->response_q);
 340		return false;
 341	}
 342
 343	cifs_dbg(FYI, "Mark tcp session as need reconnect\n");
 344	trace_smb3_reconnect(server->CurrentMid, server->conn_id,
 345			     server->hostname);
 346	server->tcpStatus = CifsNeedReconnect;
 347
 348	spin_unlock(&server->srv_lock);
 349	return true;
 350}
 351
 352/*
 353 * cifs tcp session reconnection
 354 *
 355 * mark tcp session as reconnecting so temporarily locked
 356 * mark all smb sessions as reconnecting for tcp session
 357 * reconnect tcp session
 358 * wake up waiters on reconnection? - (not needed currently)
 359 *
 360 * if mark_smb_session is passed as true, unconditionally mark
 361 * the smb session (and tcon) for reconnect as well. This value
 362 * doesn't really matter for non-multichannel scenario.
 363 *
 364 */
 365static int __cifs_reconnect(struct TCP_Server_Info *server,
 366			    bool mark_smb_session)
 367{
 368	int rc = 0;
 369
 370	if (!cifs_tcp_ses_needs_reconnect(server, 1))
 371		return 0;
 372
 373	cifs_mark_tcp_ses_conns_for_reconnect(server, mark_smb_session);
 374
 375	cifs_abort_connection(server);
 376
 377	do {
 378		try_to_freeze();
 379		cifs_server_lock(server);
 380
 381		if (!cifs_swn_set_server_dstaddr(server)) {
 382			/* resolve the hostname again to make sure that IP address is up-to-date */
 383			rc = reconn_set_ipaddr_from_hostname(server);
 384			cifs_dbg(FYI, "%s: reconn_set_ipaddr_from_hostname: rc=%d\n", __func__, rc);
 385		}
 386
 387		if (cifs_rdma_enabled(server))
 388			rc = smbd_reconnect(server);
 389		else
 390			rc = generic_ip_connect(server);
 391		if (rc) {
 392			cifs_server_unlock(server);
 393			cifs_dbg(FYI, "%s: reconnect error %d\n", __func__, rc);
 394			msleep(3000);
 395		} else {
 396			atomic_inc(&tcpSesReconnectCount);
 397			set_credits(server, 1);
 398			spin_lock(&server->srv_lock);
 399			if (server->tcpStatus != CifsExiting)
 400				server->tcpStatus = CifsNeedNegotiate;
 401			spin_unlock(&server->srv_lock);
 402			cifs_swn_reset_server_dstaddr(server);
 403			cifs_server_unlock(server);
 404			mod_delayed_work(cifsiod_wq, &server->reconnect, 0);
 405		}
 406	} while (server->tcpStatus == CifsNeedReconnect);
 407
 408	spin_lock(&server->srv_lock);
 409	if (server->tcpStatus == CifsNeedNegotiate)
 410		mod_delayed_work(cifsiod_wq, &server->echo, 0);
 411	spin_unlock(&server->srv_lock);
 412
 413	wake_up(&server->response_q);
 414	return rc;
 415}
 416
 417#ifdef CONFIG_CIFS_DFS_UPCALL
 418static int __reconnect_target_unlocked(struct TCP_Server_Info *server, const char *target)
 
 
 
 
 
 
 419{
 420	int rc;
 421	char *hostname;
 
 
 
 
 
 
 
 
 
 
 
 422
 423	if (!cifs_swn_set_server_dstaddr(server)) {
 424		if (server->hostname != target) {
 425			hostname = extract_hostname(target);
 426			if (!IS_ERR(hostname)) {
 427				kfree(server->hostname);
 428				server->hostname = hostname;
 429			} else {
 430				cifs_dbg(FYI, "%s: couldn't extract hostname or address from dfs target: %ld\n",
 431					 __func__, PTR_ERR(hostname));
 432				cifs_dbg(FYI, "%s: default to last target server: %s\n", __func__,
 433					 server->hostname);
 434			}
 435		}
 436		/* resolve the hostname again to make sure that IP address is up-to-date. */
 437		rc = reconn_set_ipaddr_from_hostname(server);
 438		cifs_dbg(FYI, "%s: reconn_set_ipaddr_from_hostname: rc=%d\n", __func__, rc);
 439	}
 440	/* Reconnect the socket */
 441	if (cifs_rdma_enabled(server))
 442		rc = smbd_reconnect(server);
 443	else
 444		rc = generic_ip_connect(server);
 445
 446	return rc;
 447}
 448
 449static int reconnect_target_unlocked(struct TCP_Server_Info *server, struct dfs_cache_tgt_list *tl,
 450				     struct dfs_cache_tgt_iterator **target_hint)
 451{
 452	int rc;
 453	struct dfs_cache_tgt_iterator *tit;
 
 
 454
 455	*target_hint = NULL;
 456
 457	/* If dfs target list is empty, then reconnect to last server */
 458	tit = dfs_cache_get_tgt_iterator(tl);
 459	if (!tit)
 460		return __reconnect_target_unlocked(server, server->hostname);
 461
 462	/* Otherwise, try every dfs target in @tl */
 463	for (; tit; tit = dfs_cache_get_next_tgt(tl, tit)) {
 464		rc = __reconnect_target_unlocked(server, dfs_cache_get_tgt_name(tit));
 465		if (!rc) {
 466			*target_hint = tit;
 467			break;
 468		}
 469	}
 470	return rc;
 471}
 472
 473static int reconnect_dfs_server(struct TCP_Server_Info *server)
 474{
 475	int rc = 0;
 476	const char *refpath = server->current_fullpath + 1;
 477	struct dfs_cache_tgt_list tl = DFS_CACHE_TGT_LIST_INIT(tl);
 478	struct dfs_cache_tgt_iterator *target_hint = NULL;
 479	int num_targets = 0;
 
 
 
 
 
 
 
 
 
 
 
 
 480
 481	/*
 482	 * Determine the number of dfs targets the referral path in @cifs_sb resolves to.
 483	 *
 484	 * smb2_reconnect() needs to know how long it should wait based upon the number of dfs
 485	 * targets (server->nr_targets).  It's also possible that the cached referral was cleared
 486	 * through /proc/fs/cifs/dfscache or the target list is empty due to server settings after
 487	 * refreshing the referral, so, in this case, default it to 1.
 488	 */
 489	if (!dfs_cache_noreq_find(refpath, NULL, &tl))
 490		num_targets = dfs_cache_get_nr_tgts(&tl);
 491	if (!num_targets)
 492		num_targets = 1;
 493
 494	if (!cifs_tcp_ses_needs_reconnect(server, num_targets))
 495		return 0;
 496
 497	/*
 498	 * Unconditionally mark all sessions & tcons for reconnect as we might be connecting to a
 499	 * different server or share during failover.  It could be improved by adding some logic to
 500	 * only do that in case it connects to a different server or share, though.
 501	 */
 502	cifs_mark_tcp_ses_conns_for_reconnect(server, true);
 503
 504	cifs_abort_connection(server);
 
 
 
 505
 506	do {
 507		try_to_freeze();
 508		cifs_server_lock(server);
 509
 510		rc = reconnect_target_unlocked(server, &tl, &target_hint);
 511		if (rc) {
 512			/* Failed to reconnect socket */
 513			cifs_server_unlock(server);
 514			cifs_dbg(FYI, "%s: reconnect error %d\n", __func__, rc);
 515			msleep(3000);
 516			continue;
 517		}
 518		/*
 519		 * Socket was created.  Update tcp session status to CifsNeedNegotiate so that a
 520		 * process waiting for reconnect will know it needs to re-establish session and tcon
 521		 * through the reconnected target server.
 522		 */
 523		atomic_inc(&tcpSesReconnectCount);
 524		set_credits(server, 1);
 525		spin_lock(&server->srv_lock);
 526		if (server->tcpStatus != CifsExiting)
 527			server->tcpStatus = CifsNeedNegotiate;
 528		spin_unlock(&server->srv_lock);
 529		cifs_swn_reset_server_dstaddr(server);
 530		cifs_server_unlock(server);
 531		mod_delayed_work(cifsiod_wq, &server->reconnect, 0);
 532	} while (server->tcpStatus == CifsNeedReconnect);
 533
 534	dfs_cache_noreq_update_tgthint(refpath, target_hint);
 535	dfs_cache_free_tgts(&tl);
 
 
 
 
 536
 537	/* Need to set up echo worker again once connection has been established */
 538	spin_lock(&server->srv_lock);
 539	if (server->tcpStatus == CifsNeedNegotiate)
 540		mod_delayed_work(cifsiod_wq, &server->echo, 0);
 541	spin_unlock(&server->srv_lock);
 
 
 542
 543	wake_up(&server->response_q);
 544	return rc;
 545}
 
 
 
 546
 547int cifs_reconnect(struct TCP_Server_Info *server, bool mark_smb_session)
 548{
 549	mutex_lock(&server->refpath_lock);
 550	if (!server->leaf_fullpath) {
 551		mutex_unlock(&server->refpath_lock);
 552		return __cifs_reconnect(server, mark_smb_session);
 553	}
 554	mutex_unlock(&server->refpath_lock);
 555
 556	return reconnect_dfs_server(server);
 
 
 
 
 557}
 558#else
 559int cifs_reconnect(struct TCP_Server_Info *server, bool mark_smb_session)
 560{
 561	return __cifs_reconnect(server, mark_smb_session);
 562}
 563#endif
 564
 565static void
 566cifs_echo_request(struct work_struct *work)
 567{
 568	int rc;
 569	struct TCP_Server_Info *server = container_of(work,
 570					struct TCP_Server_Info, echo.work);
 571
 572	/*
 573	 * We cannot send an echo if it is disabled.
 574	 * Also, no need to ping if we got a response recently.
 
 575	 */
 576
 577	if (server->tcpStatus == CifsNeedReconnect ||
 578	    server->tcpStatus == CifsExiting ||
 579	    server->tcpStatus == CifsNew ||
 580	    (server->ops->can_echo && !server->ops->can_echo(server)) ||
 581	    time_before(jiffies, server->lstrp + server->echo_interval - HZ))
 582		goto requeue_echo;
 583
 584	rc = server->ops->echo ? server->ops->echo(server) : -ENOSYS;
 585	if (rc)
 586		cifs_dbg(FYI, "Unable to send echo request to server: %s\n",
 587			 server->hostname);
 588
 589	/* Check witness registrations */
 590	cifs_swn_check();
 591
 592requeue_echo:
 593	queue_delayed_work(cifsiod_wq, &server->echo, server->echo_interval);
 594}
 595
 596static bool
 597allocate_buffers(struct TCP_Server_Info *server)
 
 598{
 599	if (!server->bigbuf) {
 600		server->bigbuf = (char *)cifs_buf_get();
 601		if (!server->bigbuf) {
 602			cifs_server_dbg(VFS, "No memory for large SMB response\n");
 
 
 603			msleep(3000);
 604			/* retry will check if exiting */
 605			return false;
 606		}
 607	} else if (server->large_buf) {
 608		/* we are reusing a dirty large buf, clear its start */
 609		memset(server->bigbuf, 0, HEADER_SIZE(server));
 610	}
 611
 612	if (!server->smallbuf) {
 613		server->smallbuf = (char *)cifs_small_buf_get();
 614		if (!server->smallbuf) {
 615			cifs_server_dbg(VFS, "No memory for SMB response\n");
 616			msleep(1000);
 617			/* retry will check if exiting */
 618			return false;
 619		}
 620		/* beginning of smb buffer is cleared in our buf_get */
 621	} else {
 622		/* if existing small buf clear beginning */
 623		memset(server->smallbuf, 0, HEADER_SIZE(server));
 624	}
 625
 
 
 
 626	return true;
 627}
 628
 629static bool
 630server_unresponsive(struct TCP_Server_Info *server)
 631{
 632	/*
 633	 * We need to wait 3 echo intervals to make sure we handle such
 634	 * situations right:
 635	 * 1s  client sends a normal SMB request
 636	 * 2s  client gets a response
 637	 * 30s echo workqueue job pops, and decides we got a response recently
 638	 *     and don't need to send another
 639	 * ...
 640	 * 65s kernel_recvmsg times out, and we see that we haven't gotten
 641	 *     a response in >60s.
 642	 */
 643	spin_lock(&server->srv_lock);
 644	if ((server->tcpStatus == CifsGood ||
 645	    server->tcpStatus == CifsNeedNegotiate) &&
 646	    (!server->ops->can_echo || server->ops->can_echo(server)) &&
 647	    time_after(jiffies, server->lstrp + 3 * server->echo_interval)) {
 648		spin_unlock(&server->srv_lock);
 649		cifs_server_dbg(VFS, "has not responded in %lu seconds. Reconnecting...\n",
 650			 (3 * server->echo_interval) / HZ);
 651		cifs_reconnect(server, false);
 652		return true;
 653	}
 654	spin_unlock(&server->srv_lock);
 655
 656	return false;
 657}
 658
 659static inline bool
 660zero_credits(struct TCP_Server_Info *server)
 661{
 662	int val;
 663
 664	spin_lock(&server->req_lock);
 665	val = server->credits + server->echo_credits + server->oplock_credits;
 666	if (server->in_flight == 0 && val == 0) {
 667		spin_unlock(&server->req_lock);
 668		return true;
 669	}
 670	spin_unlock(&server->req_lock);
 671	return false;
 672}
 673
 674static int
 675cifs_readv_from_socket(struct TCP_Server_Info *server, struct msghdr *smb_msg)
 676{
 677	int length = 0;
 678	int total_read;
 679
 680	for (total_read = 0; msg_data_left(smb_msg); total_read += length) {
 681		try_to_freeze();
 682
 683		/* reconnect if no credits and no requests in flight */
 684		if (zero_credits(server)) {
 685			cifs_reconnect(server, false);
 686			return -ECONNABORTED;
 687		}
 688
 689		if (server_unresponsive(server))
 690			return -ECONNABORTED;
 691		if (cifs_rdma_enabled(server) && server->smbd_conn)
 692			length = smbd_recv(server->smbd_conn, smb_msg);
 693		else
 694			length = sock_recvmsg(server->ssocket, smb_msg, 0);
 695
 696		spin_lock(&server->srv_lock);
 697		if (server->tcpStatus == CifsExiting) {
 698			spin_unlock(&server->srv_lock);
 699			return -ESHUTDOWN;
 700		}
 701
 702		if (server->tcpStatus == CifsNeedReconnect) {
 703			spin_unlock(&server->srv_lock);
 704			cifs_reconnect(server, false);
 705			return -ECONNABORTED;
 706		}
 707		spin_unlock(&server->srv_lock);
 708
 709		if (length == -ERESTARTSYS ||
 710		    length == -EAGAIN ||
 711		    length == -EINTR) {
 712			/*
 713			 * Minimum sleep to prevent looping, allowing socket
 714			 * to clear and app threads to set tcpStatus
 715			 * CifsNeedReconnect if server hung.
 716			 */
 717			usleep_range(1000, 2000);
 718			length = 0;
 719			continue;
 720		}
 721
 722		if (length <= 0) {
 723			cifs_dbg(FYI, "Received no data or error: %d\n", length);
 724			cifs_reconnect(server, false);
 725			return -ECONNABORTED;
 
 
 
 
 
 
 
 
 
 
 
 
 726		}
 727	}
 728	return total_read;
 729}
 730
 731int
 732cifs_read_from_socket(struct TCP_Server_Info *server, char *buf,
 733		      unsigned int to_read)
 734{
 735	struct msghdr smb_msg = {};
 736	struct kvec iov = {.iov_base = buf, .iov_len = to_read};
 737	iov_iter_kvec(&smb_msg.msg_iter, ITER_DEST, &iov, 1, to_read);
 738
 739	return cifs_readv_from_socket(server, &smb_msg);
 740}
 741
 742ssize_t
 743cifs_discard_from_socket(struct TCP_Server_Info *server, size_t to_read)
 744{
 745	struct msghdr smb_msg = {};
 746
 747	/*
 748	 *  iov_iter_discard already sets smb_msg.type and count and iov_offset
 749	 *  and cifs_readv_from_socket sets msg_control and msg_controllen
 750	 *  so little to initialize in struct msghdr
 751	 */
 752	iov_iter_discard(&smb_msg.msg_iter, ITER_DEST, to_read);
 753
 754	return cifs_readv_from_socket(server, &smb_msg);
 755}
 756
 757int
 758cifs_read_page_from_socket(struct TCP_Server_Info *server, struct page *page,
 759	unsigned int page_offset, unsigned int to_read)
 760{
 761	struct msghdr smb_msg = {};
 762	struct bio_vec bv = {
 763		.bv_page = page, .bv_len = to_read, .bv_offset = page_offset};
 764	iov_iter_bvec(&smb_msg.msg_iter, ITER_DEST, &bv, 1, to_read);
 765	return cifs_readv_from_socket(server, &smb_msg);
 766}
 767
 768static bool
 769is_smb_response(struct TCP_Server_Info *server, unsigned char type)
 770{
 771	/*
 772	 * The first byte big endian of the length field,
 773	 * is actually not part of the length but the type
 774	 * with the most common, zero, as regular data.
 775	 */
 776	switch (type) {
 777	case RFC1002_SESSION_MESSAGE:
 778		/* Regular SMB response */
 779		return true;
 780	case RFC1002_SESSION_KEEP_ALIVE:
 781		cifs_dbg(FYI, "RFC 1002 session keep alive\n");
 782		break;
 783	case RFC1002_POSITIVE_SESSION_RESPONSE:
 784		cifs_dbg(FYI, "RFC 1002 positive session response\n");
 785		break;
 786	case RFC1002_NEGATIVE_SESSION_RESPONSE:
 787		/*
 788		 * We get this from Windows 98 instead of an error on
 789		 * SMB negprot response.
 790		 */
 791		cifs_dbg(FYI, "RFC 1002 negative session response\n");
 
 792		/* give server a second to clean up */
 793		msleep(1000);
 794		/*
 795		 * Always try 445 first on reconnect since we get NACK
 796		 * on some if we ever connected to port 139 (the NACK
 797		 * is since we do not begin with RFC1001 session
 798		 * initialize frame).
 799		 */
 800		cifs_set_port((struct sockaddr *)&server->dstaddr, CIFS_PORT);
 801		cifs_reconnect(server, true);
 802		break;
 803	default:
 804		cifs_server_dbg(VFS, "RFC 1002 unknown response type 0x%x\n", type);
 805		cifs_reconnect(server, true);
 
 
 
 
 806	}
 807
 808	return false;
 809}
 810
 811void
 812dequeue_mid(struct mid_q_entry *mid, bool malformed)
 813{
 814#ifdef CONFIG_CIFS_STATS2
 815	mid->when_received = jiffies;
 816#endif
 817	spin_lock(&mid->server->mid_lock);
 818	if (!malformed)
 819		mid->mid_state = MID_RESPONSE_RECEIVED;
 820	else
 821		mid->mid_state = MID_RESPONSE_MALFORMED;
 822	/*
 823	 * Trying to handle/dequeue a mid after the send_recv()
 824	 * function has finished processing it is a bug.
 825	 */
 826	if (mid->mid_flags & MID_DELETED) {
 827		spin_unlock(&mid->server->mid_lock);
 828		pr_warn_once("trying to dequeue a deleted mid\n");
 829	} else {
 830		list_del_init(&mid->qhead);
 831		mid->mid_flags |= MID_DELETED;
 832		spin_unlock(&mid->server->mid_lock);
 833	}
 834}
 835
 836static unsigned int
 837smb2_get_credits_from_hdr(char *buffer, struct TCP_Server_Info *server)
 838{
 839	struct smb2_hdr *shdr = (struct smb2_hdr *)buffer;
 840
 841	/*
 842	 * SMB1 does not use credits.
 843	 */
 844	if (is_smb1(server))
 845		return 0;
 846
 847	return le16_to_cpu(shdr->CreditRequest);
 848}
 849
 850static void
 851handle_mid(struct mid_q_entry *mid, struct TCP_Server_Info *server,
 852	   char *buf, int malformed)
 853{
 854	if (server->ops->check_trans2 &&
 855	    server->ops->check_trans2(mid, server, buf, malformed))
 856		return;
 857	mid->credits_received = smb2_get_credits_from_hdr(buf, server);
 858	mid->resp_buf = buf;
 859	mid->large_buf = server->large_buf;
 860	/* Was previous buf put in mpx struct for multi-rsp? */
 861	if (!mid->multiRsp) {
 862		/* smb buffer will be freed by user thread */
 863		if (server->large_buf)
 864			server->bigbuf = NULL;
 865		else
 866			server->smallbuf = NULL;
 867	}
 868	dequeue_mid(mid, malformed);
 869}
 870
 871int
 872cifs_enable_signing(struct TCP_Server_Info *server, bool mnt_sign_required)
 873{
 874	bool srv_sign_required = server->sec_mode & server->vals->signing_required;
 875	bool srv_sign_enabled = server->sec_mode & server->vals->signing_enabled;
 876	bool mnt_sign_enabled;
 877
 878	/*
 879	 * Is signing required by mnt options? If not then check
 880	 * global_secflags to see if it is there.
 881	 */
 882	if (!mnt_sign_required)
 883		mnt_sign_required = ((global_secflags & CIFSSEC_MUST_SIGN) ==
 884						CIFSSEC_MUST_SIGN);
 885
 886	/*
 887	 * If signing is required then it's automatically enabled too,
 888	 * otherwise, check to see if the secflags allow it.
 889	 */
 890	mnt_sign_enabled = mnt_sign_required ? mnt_sign_required :
 891				(global_secflags & CIFSSEC_MAY_SIGN);
 892
 893	/* If server requires signing, does client allow it? */
 894	if (srv_sign_required) {
 895		if (!mnt_sign_enabled) {
 896			cifs_dbg(VFS, "Server requires signing, but it's disabled in SecurityFlags!\n");
 897			return -EOPNOTSUPP;
 898		}
 899		server->sign = true;
 
 
 
 
 
 
 
 
 
 
 
 
 900	}
 
 901
 902	/* If client requires signing, does server allow it? */
 903	if (mnt_sign_required) {
 904		if (!srv_sign_enabled) {
 905			cifs_dbg(VFS, "Server does not support signing!\n");
 906			return -EOPNOTSUPP;
 907		}
 908		server->sign = true;
 909	}
 910
 911	if (cifs_rdma_enabled(server) && server->sign)
 912		cifs_dbg(VFS, "Signing is enabled, and RDMA read/write will be disabled\n");
 913
 914	return 0;
 915}
 916
 917
 918static void clean_demultiplex_info(struct TCP_Server_Info *server)
 919{
 920	int length;
 921
 922	/* take it off the list, if it's not already */
 923	spin_lock(&server->srv_lock);
 924	list_del_init(&server->tcp_ses_list);
 925	spin_unlock(&server->srv_lock);
 926
 927	cancel_delayed_work_sync(&server->echo);
 928	cancel_delayed_work_sync(&server->resolve);
 929
 930	spin_lock(&server->srv_lock);
 931	server->tcpStatus = CifsExiting;
 932	spin_unlock(&server->srv_lock);
 933	wake_up_all(&server->response_q);
 934
 935	/* check if we have blocked requests that need to free */
 936	spin_lock(&server->req_lock);
 937	if (server->credits <= 0)
 938		server->credits = 1;
 939	spin_unlock(&server->req_lock);
 
 
 
 
 
 
 
 
 940	/*
 941	 * Although there should not be any requests blocked on this queue it
 942	 * can not hurt to be paranoid and try to wake up requests that may
 943	 * haven been blocked when more than 50 at time were on the wire to the
 944	 * same server - they now will see the session is in exit state and get
 945	 * out of SendReceive.
 946	 */
 947	wake_up_all(&server->request_q);
 948	/* give those requests time to exit */
 949	msleep(125);
 950	if (cifs_rdma_enabled(server))
 951		smbd_destroy(server);
 952	if (server->ssocket) {
 953		sock_release(server->ssocket);
 954		server->ssocket = NULL;
 955	}
 956
 957	if (!list_empty(&server->pending_mid_q)) {
 958		struct list_head dispose_list;
 959		struct mid_q_entry *mid_entry;
 960		struct list_head *tmp, *tmp2;
 961
 962		INIT_LIST_HEAD(&dispose_list);
 963		spin_lock(&server->mid_lock);
 964		list_for_each_safe(tmp, tmp2, &server->pending_mid_q) {
 965			mid_entry = list_entry(tmp, struct mid_q_entry, qhead);
 966			cifs_dbg(FYI, "Clearing mid %llu\n", mid_entry->mid);
 967			kref_get(&mid_entry->refcount);
 968			mid_entry->mid_state = MID_SHUTDOWN;
 969			list_move(&mid_entry->qhead, &dispose_list);
 970			mid_entry->mid_flags |= MID_DELETED;
 971		}
 972		spin_unlock(&server->mid_lock);
 973
 974		/* now walk dispose list and issue callbacks */
 975		list_for_each_safe(tmp, tmp2, &dispose_list) {
 976			mid_entry = list_entry(tmp, struct mid_q_entry, qhead);
 977			cifs_dbg(FYI, "Callback mid %llu\n", mid_entry->mid);
 978			list_del_init(&mid_entry->qhead);
 979			mid_entry->callback(mid_entry);
 980			release_mid(mid_entry);
 981		}
 982		/* 1/8th of sec is more than enough time for them to exit */
 983		msleep(125);
 984	}
 985
 986	if (!list_empty(&server->pending_mid_q)) {
 987		/*
 988		 * mpx threads have not exited yet give them at least the smb
 989		 * send timeout time for long ops.
 990		 *
 991		 * Due to delays on oplock break requests, we need to wait at
 992		 * least 45 seconds before giving up on a request getting a
 993		 * response and going ahead and killing cifsd.
 994		 */
 995		cifs_dbg(FYI, "Wait for exit from demultiplex thread\n");
 996		msleep(46000);
 997		/*
 998		 * If threads still have not exited they are probably never
 999		 * coming home not much else we can do but free the memory.
1000		 */
1001	}
1002
1003#ifdef CONFIG_CIFS_DFS_UPCALL
1004	kfree(server->origin_fullpath);
1005	kfree(server->leaf_fullpath);
1006#endif
1007	kfree(server);
1008
1009	length = atomic_dec_return(&tcpSesAllocCount);
1010	if (length > 0)
1011		mempool_resize(cifs_req_poolp, length + cifs_min_rcv);
 
1012}
1013
1014static int
1015standard_receive3(struct TCP_Server_Info *server, struct mid_q_entry *mid)
1016{
1017	int length;
1018	char *buf = server->smallbuf;
1019	unsigned int pdu_length = server->pdu_size;
1020
1021	/* make sure this will fit in a large buffer */
1022	if (pdu_length > CIFSMaxBufSize + MAX_HEADER_SIZE(server) -
1023	    HEADER_PREAMBLE_SIZE(server)) {
1024		cifs_server_dbg(VFS, "SMB response too long (%u bytes)\n", pdu_length);
1025		cifs_reconnect(server, true);
1026		return -ECONNABORTED;
1027	}
1028
1029	/* switch to large buffer if too big for a small one */
1030	if (pdu_length > MAX_CIFS_SMALL_BUFFER_SIZE - 4) {
1031		server->large_buf = true;
1032		memcpy(server->bigbuf, buf, server->total_read);
1033		buf = server->bigbuf;
1034	}
1035
1036	/* now read the rest */
1037	length = cifs_read_from_socket(server, buf + HEADER_SIZE(server) - 1,
1038				       pdu_length - MID_HEADER_SIZE(server));
1039
1040	if (length < 0)
1041		return length;
1042	server->total_read += length;
1043
1044	dump_smb(buf, server->total_read);
1045
1046	return cifs_handle_standard(server, mid);
1047}
1048
1049int
1050cifs_handle_standard(struct TCP_Server_Info *server, struct mid_q_entry *mid)
1051{
1052	char *buf = server->large_buf ? server->bigbuf : server->smallbuf;
1053	int rc;
1054
1055	/*
1056	 * We know that we received enough to get to the MID as we
1057	 * checked the pdu_length earlier. Now check to see
1058	 * if the rest of the header is OK.
1059	 *
1060	 * 48 bytes is enough to display the header and a little bit
1061	 * into the payload for debugging purposes.
1062	 */
1063	rc = server->ops->check_message(buf, server->total_read, server);
1064	if (rc)
1065		cifs_dump_mem("Bad SMB: ", buf,
1066			min_t(unsigned int, server->total_read, 48));
1067
1068	if (server->ops->is_session_expired &&
1069	    server->ops->is_session_expired(buf)) {
1070		cifs_reconnect(server, true);
1071		return -1;
1072	}
1073
1074	if (server->ops->is_status_pending &&
1075	    server->ops->is_status_pending(buf, server))
1076		return -1;
1077
1078	if (!mid)
1079		return rc;
1080
1081	handle_mid(mid, server, buf, rc);
1082	return 0;
1083}
1084
1085static void
1086smb2_add_credits_from_hdr(char *buffer, struct TCP_Server_Info *server)
1087{
1088	struct smb2_hdr *shdr = (struct smb2_hdr *)buffer;
1089	int scredits, in_flight;
1090
1091	/*
1092	 * SMB1 does not use credits.
1093	 */
1094	if (is_smb1(server))
1095		return;
1096
1097	if (shdr->CreditRequest) {
1098		spin_lock(&server->req_lock);
1099		server->credits += le16_to_cpu(shdr->CreditRequest);
1100		scredits = server->credits;
1101		in_flight = server->in_flight;
1102		spin_unlock(&server->req_lock);
1103		wake_up(&server->request_q);
1104
1105		trace_smb3_hdr_credits(server->CurrentMid,
1106				server->conn_id, server->hostname, scredits,
1107				le16_to_cpu(shdr->CreditRequest), in_flight);
1108		cifs_server_dbg(FYI, "%s: added %u credits total=%d\n",
1109				__func__, le16_to_cpu(shdr->CreditRequest),
1110				scredits);
1111	}
1112}
1113
1114
1115static int
1116cifs_demultiplex_thread(void *p)
1117{
1118	int i, num_mids, length;
1119	struct TCP_Server_Info *server = p;
1120	unsigned int pdu_length;
1121	unsigned int next_offset;
1122	char *buf = NULL;
 
 
1123	struct task_struct *task_to_wake = NULL;
1124	struct mid_q_entry *mids[MAX_COMPOUND];
1125	char *bufs[MAX_COMPOUND];
1126	unsigned int noreclaim_flag, num_io_timeout = 0;
 
1127
1128	noreclaim_flag = memalloc_noreclaim_save();
1129	cifs_dbg(FYI, "Demultiplex PID: %d\n", task_pid_nr(current));
1130
1131	length = atomic_inc_return(&tcpSesAllocCount);
1132	if (length > 1)
1133		mempool_resize(cifs_req_poolp, length + cifs_min_rcv);
 
1134
1135	set_freezable();
1136	allow_kernel_signal(SIGKILL);
1137	while (server->tcpStatus != CifsExiting) {
1138		if (try_to_freeze())
1139			continue;
1140
1141		if (!allocate_buffers(server))
 
1142			continue;
1143
1144		server->large_buf = false;
1145		buf = server->smallbuf;
 
 
 
 
 
 
1146		pdu_length = 4; /* enough to get RFC1001 header */
1147
1148		length = cifs_read_from_socket(server, buf, pdu_length);
1149		if (length < 0)
 
 
 
 
 
 
 
1150			continue;
 
1151
1152		if (is_smb1(server))
1153			server->total_read = length;
1154		else
1155			server->total_read = 0;
 
 
 
 
1156
1157		/*
1158		 * The right amount was read from socket - 4 bytes,
1159		 * so we can now interpret the length field.
1160		 */
1161		pdu_length = get_rfc1002_length(buf);
1162
1163		cifs_dbg(FYI, "RFC1002 header 0x%x\n", pdu_length);
1164		if (!is_smb_response(server, buf[0]))
 
 
 
 
 
 
 
1165			continue;
1166next_pdu:
1167		server->pdu_size = pdu_length;
1168
1169		/* make sure we have enough to get to the MID */
1170		if (server->pdu_size < MID_HEADER_SIZE(server)) {
1171			cifs_server_dbg(VFS, "SMB response too short (%u bytes)\n",
1172				 server->pdu_size);
1173			cifs_reconnect(server, true);
1174			continue;
1175		}
1176
1177		/* read down to the MID */
1178		length = cifs_read_from_socket(server,
1179			     buf + HEADER_PREAMBLE_SIZE(server),
1180			     MID_HEADER_SIZE(server));
1181		if (length < 0)
 
 
1182			continue;
1183		server->total_read += length;
1184
1185		if (server->ops->next_header) {
1186			next_offset = server->ops->next_header(buf);
1187			if (next_offset)
1188				server->pdu_size = next_offset;
1189		}
1190
1191		memset(mids, 0, sizeof(mids));
1192		memset(bufs, 0, sizeof(bufs));
1193		num_mids = 0;
1194
1195		if (server->ops->is_transform_hdr &&
1196		    server->ops->receive_transform &&
1197		    server->ops->is_transform_hdr(buf)) {
1198			length = server->ops->receive_transform(server,
1199								mids,
1200								bufs,
1201								&num_mids);
1202		} else {
1203			mids[0] = server->ops->find_mid(server, buf);
1204			bufs[0] = buf;
1205			num_mids = 1;
1206
1207			if (!mids[0] || !mids[0]->receive)
1208				length = standard_receive3(server, mids[0]);
1209			else
1210				length = mids[0]->receive(server, mids[0]);
1211		}
1212
1213		if (length < 0) {
1214			for (i = 0; i < num_mids; i++)
1215				if (mids[i])
1216					release_mid(mids[i]);
1217			continue;
1218		}
1219
1220		if (server->ops->is_status_io_timeout &&
1221		    server->ops->is_status_io_timeout(buf)) {
1222			num_io_timeout++;
1223			if (num_io_timeout > NUM_STATUS_IO_TIMEOUT) {
1224				cifs_reconnect(server, false);
1225				num_io_timeout = 0;
1226				continue;
1227			}
1228		}
1229
1230		server->lstrp = jiffies;
1231
1232		for (i = 0; i < num_mids; i++) {
1233			if (mids[i] != NULL) {
1234				mids[i]->resp_buf_size = server->pdu_size;
1235
1236				if (bufs[i] && server->ops->is_network_name_deleted)
1237					server->ops->is_network_name_deleted(bufs[i],
1238									server);
1239
1240				if (!mids[i]->multiRsp || mids[i]->multiEnd)
1241					mids[i]->callback(mids[i]);
1242
1243				release_mid(mids[i]);
1244			} else if (server->ops->is_oplock_break &&
1245				   server->ops->is_oplock_break(bufs[i],
1246								server)) {
1247				smb2_add_credits_from_hdr(bufs[i], server);
1248				cifs_dbg(FYI, "Received oplock break\n");
1249			} else {
1250				cifs_server_dbg(VFS, "No task to wake, unknown frame received! NumMids %d\n",
1251						atomic_read(&mid_count));
1252				cifs_dump_mem("Received Data is: ", bufs[i],
1253					      HEADER_SIZE(server));
1254				smb2_add_credits_from_hdr(bufs[i], server);
1255#ifdef CONFIG_CIFS_DEBUG2
1256				if (server->ops->dump_detail)
1257					server->ops->dump_detail(bufs[i],
1258								 server);
1259				cifs_dump_mids(server);
1260#endif /* CIFS_DEBUG2 */
1261			}
1262		}
1263
1264		if (pdu_length > server->pdu_size) {
1265			if (!allocate_buffers(server))
1266				continue;
1267			pdu_length -= server->pdu_size;
1268			server->total_read = 0;
1269			server->large_buf = false;
1270			buf = server->smallbuf;
1271			goto next_pdu;
1272		}
1273	} /* end while !EXITING */
1274
1275	/* buffer usually freed in free_mid - need to free it here on exit */
1276	cifs_buf_release(server->bigbuf);
1277	if (server->smallbuf) /* no sense logging a debug message if NULL */
1278		cifs_small_buf_release(server->smallbuf);
1279
1280	task_to_wake = xchg(&server->tsk, NULL);
1281	clean_demultiplex_info(server);
1282
1283	/* if server->tsk was NULL then wait for a signal before exiting */
1284	if (!task_to_wake) {
1285		set_current_state(TASK_INTERRUPTIBLE);
1286		while (!signal_pending(current)) {
1287			schedule();
1288			set_current_state(TASK_INTERRUPTIBLE);
1289		}
1290		set_current_state(TASK_RUNNING);
1291	}
1292
1293	memalloc_noreclaim_restore(noreclaim_flag);
1294	module_put_and_kthread_exit(0);
1295}
1296
1297/*
1298 * Returns true if srcaddr isn't specified and rhs isn't specified, or
1299 * if srcaddr is specified and matches the IP address of the rhs argument
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1300 */
1301bool
1302cifs_match_ipaddr(struct sockaddr *srcaddr, struct sockaddr *rhs)
1303{
1304	switch (srcaddr->sa_family) {
1305	case AF_UNSPEC:
1306		return (rhs->sa_family == AF_UNSPEC);
1307	case AF_INET: {
1308		struct sockaddr_in *saddr4 = (struct sockaddr_in *)srcaddr;
1309		struct sockaddr_in *vaddr4 = (struct sockaddr_in *)rhs;
1310		return (saddr4->sin_addr.s_addr == vaddr4->sin_addr.s_addr);
1311	}
1312	case AF_INET6: {
1313		struct sockaddr_in6 *saddr6 = (struct sockaddr_in6 *)srcaddr;
1314		struct sockaddr_in6 *vaddr6 = (struct sockaddr_in6 *)rhs;
1315		return ipv6_addr_equal(&saddr6->sin6_addr, &vaddr6->sin6_addr);
1316	}
1317	default:
1318		WARN_ON(1);
1319		return false; /* don't expect to be here */
1320	}
1321}
1322
1323/*
1324 * If no port is specified in addr structure, we try to match with 445 port
1325 * and if it fails - with 139 ports. It should be called only if address
1326 * families of server and addr are equal.
1327 */
1328static bool
1329match_port(struct TCP_Server_Info *server, struct sockaddr *addr)
1330{
1331	__be16 port, *sport;
1332
1333	/* SMBDirect manages its own ports, don't match it here */
1334	if (server->rdma)
1335		return true;
1336
1337	switch (addr->sa_family) {
1338	case AF_INET:
1339		sport = &((struct sockaddr_in *) &server->dstaddr)->sin_port;
1340		port = ((struct sockaddr_in *) addr)->sin_port;
1341		break;
1342	case AF_INET6:
1343		sport = &((struct sockaddr_in6 *) &server->dstaddr)->sin6_port;
1344		port = ((struct sockaddr_in6 *) addr)->sin6_port;
1345		break;
1346	default:
1347		WARN_ON(1);
1348		return false;
1349	}
1350
1351	if (!port) {
1352		port = htons(CIFS_PORT);
1353		if (port == *sport)
1354			return true;
1355
1356		port = htons(RFC1001_PORT);
1357	}
1358
1359	return port == *sport;
1360}
1361
1362static bool match_server_address(struct TCP_Server_Info *server, struct sockaddr *addr)
 
 
1363{
1364	switch (addr->sa_family) {
1365	case AF_INET: {
1366		struct sockaddr_in *addr4 = (struct sockaddr_in *)addr;
1367		struct sockaddr_in *srv_addr4 =
1368					(struct sockaddr_in *)&server->dstaddr;
1369
1370		if (addr4->sin_addr.s_addr != srv_addr4->sin_addr.s_addr)
1371			return false;
1372		break;
1373	}
1374	case AF_INET6: {
1375		struct sockaddr_in6 *addr6 = (struct sockaddr_in6 *)addr;
1376		struct sockaddr_in6 *srv_addr6 =
1377					(struct sockaddr_in6 *)&server->dstaddr;
1378
1379		if (!ipv6_addr_equal(&addr6->sin6_addr,
1380				     &srv_addr6->sin6_addr))
1381			return false;
1382		if (addr6->sin6_scope_id != srv_addr6->sin6_scope_id)
1383			return false;
1384		break;
1385	}
1386	default:
1387		WARN_ON(1);
1388		return false; /* don't expect to be here */
1389	}
1390
 
 
 
1391	return true;
1392}
1393
1394static bool
1395match_security(struct TCP_Server_Info *server, struct smb3_fs_context *ctx)
1396{
1397	/*
1398	 * The select_sectype function should either return the ctx->sectype
1399	 * that was specified, or "Unspecified" if that sectype was not
1400	 * compatible with the given NEGOTIATE request.
1401	 */
1402	if (server->ops->select_sectype(server, ctx->sectype)
1403	     == Unspecified)
1404		return false;
1405
1406	/*
1407	 * Now check if signing mode is acceptable. No need to check
1408	 * global_secflags at this point since if MUST_SIGN is set then
1409	 * the server->sign had better be too.
1410	 */
1411	if (ctx->sign && !server->sign)
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1412		return false;
 
1413
1414	return true;
1415}
 
 
 
 
 
 
1416
1417static bool dfs_src_pathname_equal(const char *s1, const char *s2)
1418{
1419	if (strlen(s1) != strlen(s2))
1420		return false;
1421	for (; *s1; s1++, s2++) {
1422		if (*s1 == '/' || *s1 == '\\') {
1423			if (*s2 != '/' && *s2 != '\\')
1424				return false;
1425		} else if (tolower(*s1) != tolower(*s2))
1426			return false;
1427	}
1428	return true;
1429}
1430
1431/* this function must be called with srv_lock held */
1432static int match_server(struct TCP_Server_Info *server, struct smb3_fs_context *ctx,
1433			bool dfs_super_cmp)
1434{
1435	struct sockaddr *addr = (struct sockaddr *)&ctx->dstaddr;
1436
1437	if (ctx->nosharesock)
1438		return 0;
1439
1440	/* this server does not share socket */
1441	if (server->nosharesock)
1442		return 0;
1443
1444	/* If multidialect negotiation see if existing sessions match one */
1445	if (strcmp(ctx->vals->version_string, SMB3ANY_VERSION_STRING) == 0) {
1446		if (server->vals->protocol_id < SMB30_PROT_ID)
1447			return 0;
1448	} else if (strcmp(ctx->vals->version_string,
1449		   SMBDEFAULT_VERSION_STRING) == 0) {
1450		if (server->vals->protocol_id < SMB21_PROT_ID)
1451			return 0;
1452	} else if ((server->vals != ctx->vals) || (server->ops != ctx->ops))
1453		return 0;
1454
1455	if (!net_eq(cifs_net_ns(server), current->nsproxy->net_ns))
1456		return 0;
1457
1458	if (!cifs_match_ipaddr((struct sockaddr *)&ctx->srcaddr,
1459			       (struct sockaddr *)&server->srcaddr))
1460		return 0;
1461	/*
1462	 * When matching DFS superblocks, we only check for original source pathname as the
1463	 * currently connected target might be different than the one parsed earlier in i.e.
1464	 * mount.cifs(8).
1465	 */
1466	if (dfs_super_cmp) {
1467		if (!ctx->source || !server->origin_fullpath ||
1468		    !dfs_src_pathname_equal(server->origin_fullpath, ctx->source))
1469			return 0;
1470	} else {
1471		/* Skip addr, hostname and port matching for DFS connections */
1472		if (server->leaf_fullpath) {
1473			if (!ctx->leaf_fullpath ||
1474			    strcasecmp(server->leaf_fullpath, ctx->leaf_fullpath))
1475				return 0;
1476		} else if (strcasecmp(server->hostname, ctx->server_hostname) ||
1477			   !match_server_address(server, addr) ||
1478			   !match_port(server, addr)) {
1479			return 0;
1480		}
1481	}
1482
1483	if (!match_security(server, ctx))
1484		return 0;
1485
1486	if (server->echo_interval != ctx->echo_interval * HZ)
1487		return 0;
1488
1489	if (server->rdma != ctx->rdma)
1490		return 0;
1491
1492	if (server->ignore_signature != ctx->ignore_signature)
1493		return 0;
1494
1495	if (server->min_offload != ctx->min_offload)
1496		return 0;
1497
1498	return 1;
1499}
1500
1501struct TCP_Server_Info *
1502cifs_find_tcp_session(struct smb3_fs_context *ctx)
1503{
1504	struct TCP_Server_Info *server;
1505
1506	spin_lock(&cifs_tcp_ses_lock);
1507	list_for_each_entry(server, &cifs_tcp_ses_list, tcp_ses_list) {
1508		spin_lock(&server->srv_lock);
1509		/*
1510		 * Skip ses channels since they're only handled in lower layers
1511		 * (e.g. cifs_send_recv).
1512		 */
1513		if (CIFS_SERVER_IS_CHAN(server) || !match_server(server, ctx, false)) {
1514			spin_unlock(&server->srv_lock);
1515			continue;
1516		}
1517		spin_unlock(&server->srv_lock);
1518
1519		++server->srv_count;
1520		spin_unlock(&cifs_tcp_ses_lock);
1521		cifs_dbg(FYI, "Existing tcp session with server found\n");
1522		return server;
1523	}
1524	spin_unlock(&cifs_tcp_ses_lock);
1525	return NULL;
1526}
1527
1528void
1529cifs_put_tcp_session(struct TCP_Server_Info *server, int from_reconnect)
1530{
1531	struct task_struct *task;
1532
1533	spin_lock(&cifs_tcp_ses_lock);
1534	if (--server->srv_count > 0) {
1535		spin_unlock(&cifs_tcp_ses_lock);
1536		return;
1537	}
1538
1539	/* srv_count can never go negative */
1540	WARN_ON(server->srv_count < 0);
1541
1542	put_net(cifs_net_ns(server));
1543
1544	list_del_init(&server->tcp_ses_list);
1545	spin_unlock(&cifs_tcp_ses_lock);
1546
1547	/* For secondary channels, we pick up ref-count on the primary server */
1548	if (CIFS_SERVER_IS_CHAN(server))
1549		cifs_put_tcp_session(server->primary_server, from_reconnect);
1550
1551	cancel_delayed_work_sync(&server->echo);
1552	cancel_delayed_work_sync(&server->resolve);
1553
1554	if (from_reconnect)
1555		/*
1556		 * Avoid deadlock here: reconnect work calls
1557		 * cifs_put_tcp_session() at its end. Need to be sure
1558		 * that reconnect work does nothing with server pointer after
1559		 * that step.
1560		 */
1561		cancel_delayed_work(&server->reconnect);
1562	else
1563		cancel_delayed_work_sync(&server->reconnect);
1564
1565	spin_lock(&server->srv_lock);
1566	server->tcpStatus = CifsExiting;
1567	spin_unlock(&server->srv_lock);
1568
1569	cifs_crypto_secmech_release(server);
 
1570
1571	kfree_sensitive(server->session_key.response);
1572	server->session_key.response = NULL;
1573	server->session_key.len = 0;
1574	kfree(server->hostname);
1575	server->hostname = NULL;
1576
1577	task = xchg(&server->tsk, NULL);
1578	if (task)
1579		send_sig(SIGKILL, task, 1);
1580}
1581
1582struct TCP_Server_Info *
1583cifs_get_tcp_session(struct smb3_fs_context *ctx,
1584		     struct TCP_Server_Info *primary_server)
1585{
1586	struct TCP_Server_Info *tcp_ses = NULL;
 
 
 
1587	int rc;
1588
1589	cifs_dbg(FYI, "UNC: %s\n", ctx->UNC);
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1590
1591	/* see if we already have a matching tcp_ses */
1592	tcp_ses = cifs_find_tcp_session(ctx);
1593	if (tcp_ses)
1594		return tcp_ses;
1595
1596	tcp_ses = kzalloc(sizeof(struct TCP_Server_Info), GFP_KERNEL);
1597	if (!tcp_ses) {
1598		rc = -ENOMEM;
1599		goto out_err;
1600	}
1601
1602	tcp_ses->hostname = kstrdup(ctx->server_hostname, GFP_KERNEL);
1603	if (!tcp_ses->hostname) {
1604		rc = -ENOMEM;
1605		goto out_err;
1606	}
1607
1608	if (ctx->leaf_fullpath) {
1609		tcp_ses->leaf_fullpath = kstrdup(ctx->leaf_fullpath, GFP_KERNEL);
1610		if (!tcp_ses->leaf_fullpath) {
1611			rc = -ENOMEM;
1612			goto out_err;
1613		}
1614		tcp_ses->current_fullpath = tcp_ses->leaf_fullpath;
1615	}
1616
1617	if (ctx->nosharesock)
1618		tcp_ses->nosharesock = true;
1619
1620	tcp_ses->ops = ctx->ops;
1621	tcp_ses->vals = ctx->vals;
1622	cifs_set_net_ns(tcp_ses, get_net(current->nsproxy->net_ns));
1623
1624	tcp_ses->conn_id = atomic_inc_return(&tcpSesNextId);
1625	tcp_ses->noblockcnt = ctx->rootfs;
1626	tcp_ses->noblocksnd = ctx->noblocksnd || ctx->rootfs;
1627	tcp_ses->noautotune = ctx->noautotune;
1628	tcp_ses->tcp_nodelay = ctx->sockopt_tcp_nodelay;
1629	tcp_ses->rdma = ctx->rdma;
1630	tcp_ses->in_flight = 0;
1631	tcp_ses->max_in_flight = 0;
1632	tcp_ses->credits = 1;
1633	if (primary_server) {
1634		spin_lock(&cifs_tcp_ses_lock);
1635		++primary_server->srv_count;
1636		spin_unlock(&cifs_tcp_ses_lock);
1637		tcp_ses->primary_server = primary_server;
1638	}
1639	init_waitqueue_head(&tcp_ses->response_q);
1640	init_waitqueue_head(&tcp_ses->request_q);
1641	INIT_LIST_HEAD(&tcp_ses->pending_mid_q);
1642	mutex_init(&tcp_ses->_srv_mutex);
1643	memcpy(tcp_ses->workstation_RFC1001_name,
1644		ctx->source_rfc1001_name, RFC1001_NAME_LEN_WITH_NULL);
1645	memcpy(tcp_ses->server_RFC1001_name,
1646		ctx->target_rfc1001_name, RFC1001_NAME_LEN_WITH_NULL);
1647	tcp_ses->session_estab = false;
1648	tcp_ses->sequence_number = 0;
1649	tcp_ses->reconnect_instance = 1;
1650	tcp_ses->lstrp = jiffies;
1651	tcp_ses->compress_algorithm = cpu_to_le16(ctx->compression);
1652	spin_lock_init(&tcp_ses->req_lock);
1653	spin_lock_init(&tcp_ses->srv_lock);
1654	spin_lock_init(&tcp_ses->mid_lock);
1655	INIT_LIST_HEAD(&tcp_ses->tcp_ses_list);
1656	INIT_LIST_HEAD(&tcp_ses->smb_ses_list);
1657	INIT_DELAYED_WORK(&tcp_ses->echo, cifs_echo_request);
1658	INIT_DELAYED_WORK(&tcp_ses->resolve, cifs_resolve_server);
1659	INIT_DELAYED_WORK(&tcp_ses->reconnect, smb2_reconnect_server);
1660	mutex_init(&tcp_ses->reconnect_mutex);
1661#ifdef CONFIG_CIFS_DFS_UPCALL
1662	mutex_init(&tcp_ses->refpath_lock);
1663#endif
1664	memcpy(&tcp_ses->srcaddr, &ctx->srcaddr,
1665	       sizeof(tcp_ses->srcaddr));
1666	memcpy(&tcp_ses->dstaddr, &ctx->dstaddr,
1667		sizeof(tcp_ses->dstaddr));
1668	if (ctx->use_client_guid)
1669		memcpy(tcp_ses->client_guid, ctx->client_guid,
1670		       SMB2_CLIENT_GUID_SIZE);
1671	else
1672		generate_random_uuid(tcp_ses->client_guid);
1673	/*
1674	 * at this point we are the only ones with the pointer
1675	 * to the struct since the kernel thread not created yet
1676	 * no need to spinlock this init of tcpStatus or srv_count
1677	 */
1678	tcp_ses->tcpStatus = CifsNew;
 
 
1679	++tcp_ses->srv_count;
1680
1681	if (ctx->echo_interval >= SMB_ECHO_INTERVAL_MIN &&
1682		ctx->echo_interval <= SMB_ECHO_INTERVAL_MAX)
1683		tcp_ses->echo_interval = ctx->echo_interval * HZ;
1684	else
1685		tcp_ses->echo_interval = SMB_ECHO_INTERVAL_DEFAULT * HZ;
1686	if (tcp_ses->rdma) {
1687#ifndef CONFIG_CIFS_SMB_DIRECT
1688		cifs_dbg(VFS, "CONFIG_CIFS_SMB_DIRECT is not enabled\n");
1689		rc = -ENOENT;
1690		goto out_err_crypto_release;
1691#endif
1692		tcp_ses->smbd_conn = smbd_get_connection(
1693			tcp_ses, (struct sockaddr *)&ctx->dstaddr);
1694		if (tcp_ses->smbd_conn) {
1695			cifs_dbg(VFS, "RDMA transport established\n");
1696			rc = 0;
1697			goto smbd_connected;
1698		} else {
1699			rc = -ENOENT;
1700			goto out_err_crypto_release;
1701		}
1702	}
1703	rc = ip_connect(tcp_ses);
1704	if (rc < 0) {
1705		cifs_dbg(VFS, "Error connecting to socket. Aborting operation.\n");
1706		goto out_err_crypto_release;
1707	}
1708smbd_connected:
1709	/*
1710	 * since we're in a cifs function already, we know that
1711	 * this will succeed. No need for try_module_get().
1712	 */
1713	__module_get(THIS_MODULE);
1714	tcp_ses->tsk = kthread_run(cifs_demultiplex_thread,
1715				  tcp_ses, "cifsd");
1716	if (IS_ERR(tcp_ses->tsk)) {
1717		rc = PTR_ERR(tcp_ses->tsk);
1718		cifs_dbg(VFS, "error %d create cifsd thread\n", rc);
1719		module_put(THIS_MODULE);
1720		goto out_err_crypto_release;
1721	}
1722	tcp_ses->min_offload = ctx->min_offload;
1723	/*
1724	 * at this point we are the only ones with the pointer
1725	 * to the struct since the kernel thread not created yet
1726	 * no need to spinlock this update of tcpStatus
1727	 */
1728	spin_lock(&tcp_ses->srv_lock);
1729	tcp_ses->tcpStatus = CifsNeedNegotiate;
1730	spin_unlock(&tcp_ses->srv_lock);
1731
1732	if ((ctx->max_credits < 20) || (ctx->max_credits > 60000))
1733		tcp_ses->max_credits = SMB2_MAX_CREDITS_AVAILABLE;
1734	else
1735		tcp_ses->max_credits = ctx->max_credits;
1736
1737	tcp_ses->nr_targets = 1;
1738	tcp_ses->ignore_signature = ctx->ignore_signature;
1739	/* thread spawned, put it on the list */
1740	spin_lock(&cifs_tcp_ses_lock);
1741	list_add(&tcp_ses->tcp_ses_list, &cifs_tcp_ses_list);
1742	spin_unlock(&cifs_tcp_ses_lock);
1743
 
 
1744	/* queue echo request delayed work */
1745	queue_delayed_work(cifsiod_wq, &tcp_ses->echo, tcp_ses->echo_interval);
1746
1747	/* queue dns resolution delayed work */
1748	cifs_dbg(FYI, "%s: next dns resolution scheduled for %d seconds in the future\n",
1749		 __func__, SMB_DNS_RESOLVE_INTERVAL_DEFAULT);
1750
1751	queue_delayed_work(cifsiod_wq, &tcp_ses->resolve, (SMB_DNS_RESOLVE_INTERVAL_DEFAULT * HZ));
1752
1753	return tcp_ses;
1754
1755out_err_crypto_release:
1756	cifs_crypto_secmech_release(tcp_ses);
1757
1758	put_net(cifs_net_ns(tcp_ses));
1759
1760out_err:
1761	if (tcp_ses) {
1762		if (CIFS_SERVER_IS_CHAN(tcp_ses))
1763			cifs_put_tcp_session(tcp_ses->primary_server, false);
1764		kfree(tcp_ses->hostname);
1765		kfree(tcp_ses->leaf_fullpath);
1766		if (tcp_ses->ssocket)
1767			sock_release(tcp_ses->ssocket);
1768		kfree(tcp_ses);
1769	}
1770	return ERR_PTR(rc);
1771}
1772
1773/* this function must be called with ses_lock held */
1774static int match_session(struct cifs_ses *ses, struct smb3_fs_context *ctx)
1775{
1776	if (ctx->sectype != Unspecified &&
1777	    ctx->sectype != ses->sectype)
1778		return 0;
1779
1780	/*
1781	 * If an existing session is limited to less channels than
1782	 * requested, it should not be reused
1783	 */
1784	spin_lock(&ses->chan_lock);
1785	if (ses->chan_max < ctx->max_channels) {
1786		spin_unlock(&ses->chan_lock);
1787		return 0;
1788	}
1789	spin_unlock(&ses->chan_lock);
1790
1791	switch (ses->sectype) {
1792	case Kerberos:
1793		if (!uid_eq(ctx->cred_uid, ses->cred_uid))
1794			return 0;
1795		break;
1796	default:
1797		/* NULL username means anonymous session */
1798		if (ses->user_name == NULL) {
1799			if (!ctx->nullauth)
1800				return 0;
1801			break;
1802		}
1803
1804		/* anything else takes username/password */
1805		if (strncmp(ses->user_name,
1806			    ctx->username ? ctx->username : "",
1807			    CIFS_MAX_USERNAME_LEN))
 
1808			return 0;
1809		if ((ctx->username && strlen(ctx->username) != 0) &&
1810		    ses->password != NULL &&
1811		    strncmp(ses->password,
1812			    ctx->password ? ctx->password : "",
1813			    CIFS_MAX_PASSWORD_LEN))
1814			return 0;
1815	}
1816	return 1;
1817}
1818
1819/**
1820 * cifs_setup_ipc - helper to setup the IPC tcon for the session
1821 * @ses: smb session to issue the request on
1822 * @ctx: the superblock configuration context to use for building the
1823 *       new tree connection for the IPC (interprocess communication RPC)
1824 *
1825 * A new IPC connection is made and stored in the session
1826 * tcon_ipc. The IPC tcon has the same lifetime as the session.
1827 */
1828static int
1829cifs_setup_ipc(struct cifs_ses *ses, struct smb3_fs_context *ctx)
1830{
1831	int rc = 0, xid;
1832	struct cifs_tcon *tcon;
1833	char unc[SERVER_NAME_LENGTH + sizeof("//x/IPC$")] = {0};
1834	bool seal = false;
1835	struct TCP_Server_Info *server = ses->server;
1836
1837	/*
1838	 * If the mount request that resulted in the creation of the
1839	 * session requires encryption, force IPC to be encrypted too.
1840	 */
1841	if (ctx->seal) {
1842		if (server->capabilities & SMB2_GLOBAL_CAP_ENCRYPTION)
1843			seal = true;
1844		else {
1845			cifs_server_dbg(VFS,
1846				 "IPC: server doesn't support encryption\n");
1847			return -EOPNOTSUPP;
1848		}
1849	}
1850
1851	tcon = tconInfoAlloc();
1852	if (tcon == NULL)
1853		return -ENOMEM;
1854
1855	scnprintf(unc, sizeof(unc), "\\\\%s\\IPC$", server->hostname);
1856
1857	xid = get_xid();
1858	tcon->ses = ses;
1859	tcon->ipc = true;
1860	tcon->seal = seal;
1861	rc = server->ops->tree_connect(xid, ses, unc, tcon, ctx->local_nls);
1862	free_xid(xid);
1863
1864	if (rc) {
1865		cifs_server_dbg(VFS, "failed to connect to IPC (rc=%d)\n", rc);
1866		tconInfoFree(tcon);
1867		goto out;
1868	}
1869
1870	cifs_dbg(FYI, "IPC tcon rc=%d ipc tid=0x%x\n", rc, tcon->tid);
1871
1872	spin_lock(&tcon->tc_lock);
1873	tcon->status = TID_GOOD;
1874	spin_unlock(&tcon->tc_lock);
1875	ses->tcon_ipc = tcon;
1876out:
1877	return rc;
1878}
1879
1880/**
1881 * cifs_free_ipc - helper to release the session IPC tcon
1882 * @ses: smb session to unmount the IPC from
1883 *
1884 * Needs to be called everytime a session is destroyed.
1885 *
1886 * On session close, the IPC is closed and the server must release all tcons of the session.
1887 * No need to send a tree disconnect here.
1888 *
1889 * Besides, it will make the server to not close durable and resilient files on session close, as
1890 * specified in MS-SMB2 3.3.5.6 Receiving an SMB2 LOGOFF Request.
1891 */
1892static int
1893cifs_free_ipc(struct cifs_ses *ses)
1894{
1895	struct cifs_tcon *tcon = ses->tcon_ipc;
1896
1897	if (tcon == NULL)
1898		return 0;
1899
1900	tconInfoFree(tcon);
1901	ses->tcon_ipc = NULL;
1902	return 0;
1903}
1904
1905static struct cifs_ses *
1906cifs_find_smb_ses(struct TCP_Server_Info *server, struct smb3_fs_context *ctx)
1907{
1908	struct cifs_ses *ses;
1909
1910	spin_lock(&cifs_tcp_ses_lock);
1911	list_for_each_entry(ses, &server->smb_ses_list, smb_ses_list) {
1912		spin_lock(&ses->ses_lock);
1913		if (ses->ses_status == SES_EXITING) {
1914			spin_unlock(&ses->ses_lock);
1915			continue;
1916		}
1917		if (!match_session(ses, ctx)) {
1918			spin_unlock(&ses->ses_lock);
1919			continue;
1920		}
1921		spin_unlock(&ses->ses_lock);
1922
1923		++ses->ses_count;
1924		spin_unlock(&cifs_tcp_ses_lock);
1925		return ses;
1926	}
1927	spin_unlock(&cifs_tcp_ses_lock);
1928	return NULL;
1929}
1930
1931void cifs_put_smb_ses(struct cifs_ses *ses)
 
1932{
1933	unsigned int rc, xid;
1934	unsigned int chan_count;
1935	struct TCP_Server_Info *server = ses->server;
1936
1937	spin_lock(&ses->ses_lock);
1938	if (ses->ses_status == SES_EXITING) {
1939		spin_unlock(&ses->ses_lock);
1940		return;
1941	}
1942	spin_unlock(&ses->ses_lock);
1943
1944	cifs_dbg(FYI, "%s: ses_count=%d\n", __func__, ses->ses_count);
1945	cifs_dbg(FYI,
1946		 "%s: ses ipc: %s\n", __func__, ses->tcon_ipc ? ses->tcon_ipc->tree_name : "NONE");
1947
1948	spin_lock(&cifs_tcp_ses_lock);
1949	if (--ses->ses_count > 0) {
1950		spin_unlock(&cifs_tcp_ses_lock);
1951		return;
1952	}
1953	spin_unlock(&cifs_tcp_ses_lock);
1954
1955	/* ses_count can never go negative */
1956	WARN_ON(ses->ses_count < 0);
1957
1958	if (ses->ses_status == SES_GOOD)
1959		ses->ses_status = SES_EXITING;
1960
1961	cifs_free_ipc(ses);
1962
1963	if (ses->ses_status == SES_EXITING && server->ops->logoff) {
1964		xid = get_xid();
1965		rc = server->ops->logoff(xid, ses);
1966		if (rc)
1967			cifs_server_dbg(VFS, "%s: Session Logoff failure rc=%d\n",
1968				__func__, rc);
1969		_free_xid(xid);
1970	}
1971
1972	spin_lock(&cifs_tcp_ses_lock);
1973	list_del_init(&ses->smb_ses_list);
1974	spin_unlock(&cifs_tcp_ses_lock);
1975
1976	chan_count = ses->chan_count;
1977
1978	/* close any extra channels */
1979	if (chan_count > 1) {
1980		int i;
1981
1982		for (i = 1; i < chan_count; i++) {
1983			if (ses->chans[i].iface) {
1984				kref_put(&ses->chans[i].iface->refcount, release_iface);
1985				ses->chans[i].iface = NULL;
1986			}
1987			cifs_put_tcp_session(ses->chans[i].server, 0);
1988			ses->chans[i].server = NULL;
1989		}
1990	}
1991
1992	sesInfoFree(ses);
1993	cifs_put_tcp_session(server, 0);
1994}
1995
1996#ifdef CONFIG_KEYS
1997
1998/* strlen("cifs:a:") + CIFS_MAX_DOMAINNAME_LEN + 1 */
1999#define CIFSCREDS_DESC_SIZE (7 + CIFS_MAX_DOMAINNAME_LEN + 1)
2000
2001/* Populate username and pw fields from keyring if possible */
2002static int
2003cifs_set_cifscreds(struct smb3_fs_context *ctx, struct cifs_ses *ses)
2004{
2005	int rc = 0;
2006	int is_domain = 0;
2007	const char *delim, *payload;
2008	char *desc;
2009	ssize_t len;
2010	struct key *key;
2011	struct TCP_Server_Info *server = ses->server;
2012	struct sockaddr_in *sa;
2013	struct sockaddr_in6 *sa6;
2014	const struct user_key_payload *upayload;
2015
2016	desc = kmalloc(CIFSCREDS_DESC_SIZE, GFP_KERNEL);
2017	if (!desc)
2018		return -ENOMEM;
2019
2020	/* try to find an address key first */
2021	switch (server->dstaddr.ss_family) {
2022	case AF_INET:
2023		sa = (struct sockaddr_in *)&server->dstaddr;
2024		sprintf(desc, "cifs:a:%pI4", &sa->sin_addr.s_addr);
2025		break;
2026	case AF_INET6:
2027		sa6 = (struct sockaddr_in6 *)&server->dstaddr;
2028		sprintf(desc, "cifs:a:%pI6c", &sa6->sin6_addr.s6_addr);
2029		break;
2030	default:
2031		cifs_dbg(FYI, "Bad ss_family (%hu)\n",
2032			 server->dstaddr.ss_family);
2033		rc = -EINVAL;
2034		goto out_err;
2035	}
2036
2037	cifs_dbg(FYI, "%s: desc=%s\n", __func__, desc);
2038	key = request_key(&key_type_logon, desc, "");
2039	if (IS_ERR(key)) {
2040		if (!ses->domainName) {
2041			cifs_dbg(FYI, "domainName is NULL\n");
2042			rc = PTR_ERR(key);
2043			goto out_err;
2044		}
2045
2046		/* didn't work, try to find a domain key */
2047		sprintf(desc, "cifs:d:%s", ses->domainName);
2048		cifs_dbg(FYI, "%s: desc=%s\n", __func__, desc);
2049		key = request_key(&key_type_logon, desc, "");
2050		if (IS_ERR(key)) {
2051			rc = PTR_ERR(key);
2052			goto out_err;
2053		}
2054		is_domain = 1;
2055	}
2056
2057	down_read(&key->sem);
2058	upayload = user_key_payload_locked(key);
2059	if (IS_ERR_OR_NULL(upayload)) {
2060		rc = upayload ? PTR_ERR(upayload) : -EINVAL;
2061		goto out_key_put;
2062	}
2063
2064	/* find first : in payload */
2065	payload = upayload->data;
2066	delim = strnchr(payload, upayload->datalen, ':');
2067	cifs_dbg(FYI, "payload=%s\n", payload);
2068	if (!delim) {
2069		cifs_dbg(FYI, "Unable to find ':' in payload (datalen=%d)\n",
2070			 upayload->datalen);
2071		rc = -EINVAL;
2072		goto out_key_put;
2073	}
2074
2075	len = delim - payload;
2076	if (len > CIFS_MAX_USERNAME_LEN || len <= 0) {
2077		cifs_dbg(FYI, "Bad value from username search (len=%zd)\n",
2078			 len);
2079		rc = -EINVAL;
2080		goto out_key_put;
2081	}
2082
2083	ctx->username = kstrndup(payload, len, GFP_KERNEL);
2084	if (!ctx->username) {
2085		cifs_dbg(FYI, "Unable to allocate %zd bytes for username\n",
2086			 len);
2087		rc = -ENOMEM;
2088		goto out_key_put;
2089	}
2090	cifs_dbg(FYI, "%s: username=%s\n", __func__, ctx->username);
2091
2092	len = key->datalen - (len + 1);
2093	if (len > CIFS_MAX_PASSWORD_LEN || len <= 0) {
2094		cifs_dbg(FYI, "Bad len for password search (len=%zd)\n", len);
2095		rc = -EINVAL;
2096		kfree(ctx->username);
2097		ctx->username = NULL;
2098		goto out_key_put;
2099	}
2100
2101	++delim;
2102	ctx->password = kstrndup(delim, len, GFP_KERNEL);
2103	if (!ctx->password) {
2104		cifs_dbg(FYI, "Unable to allocate %zd bytes for password\n",
2105			 len);
2106		rc = -ENOMEM;
2107		kfree(ctx->username);
2108		ctx->username = NULL;
2109		goto out_key_put;
2110	}
2111
2112	/*
2113	 * If we have a domain key then we must set the domainName in the
2114	 * for the request.
2115	 */
2116	if (is_domain && ses->domainName) {
2117		ctx->domainname = kstrdup(ses->domainName, GFP_KERNEL);
2118		if (!ctx->domainname) {
2119			cifs_dbg(FYI, "Unable to allocate %zd bytes for domain\n",
2120				 len);
2121			rc = -ENOMEM;
2122			kfree(ctx->username);
2123			ctx->username = NULL;
2124			kfree_sensitive(ctx->password);
2125			ctx->password = NULL;
2126			goto out_key_put;
2127		}
2128	}
2129
2130	strscpy(ctx->workstation_name, ses->workstation_name, sizeof(ctx->workstation_name));
2131
2132out_key_put:
2133	up_read(&key->sem);
2134	key_put(key);
2135out_err:
2136	kfree(desc);
2137	cifs_dbg(FYI, "%s: returning %d\n", __func__, rc);
2138	return rc;
2139}
2140#else /* ! CONFIG_KEYS */
2141static inline int
2142cifs_set_cifscreds(struct smb3_fs_context *ctx __attribute__((unused)),
2143		   struct cifs_ses *ses __attribute__((unused)))
2144{
2145	return -ENOSYS;
2146}
2147#endif /* CONFIG_KEYS */
2148
2149/**
2150 * cifs_get_smb_ses - get a session matching @ctx data from @server
2151 * @server: server to setup the session to
2152 * @ctx: superblock configuration context to use to setup the session
2153 *
2154 * This function assumes it is being called from cifs_mount() where we
2155 * already got a server reference (server refcount +1). See
2156 * cifs_get_tcon() for refcount explanations.
2157 */
2158struct cifs_ses *
2159cifs_get_smb_ses(struct TCP_Server_Info *server, struct smb3_fs_context *ctx)
2160{
2161	int rc = 0;
2162	unsigned int xid;
2163	struct cifs_ses *ses;
2164	struct sockaddr_in *addr = (struct sockaddr_in *)&server->dstaddr;
2165	struct sockaddr_in6 *addr6 = (struct sockaddr_in6 *)&server->dstaddr;
2166
2167	xid = get_xid();
2168
2169	ses = cifs_find_smb_ses(server, ctx);
2170	if (ses) {
2171		cifs_dbg(FYI, "Existing smb sess found (status=%d)\n",
2172			 ses->ses_status);
2173
2174		spin_lock(&ses->chan_lock);
2175		if (cifs_chan_needs_reconnect(ses, server)) {
2176			spin_unlock(&ses->chan_lock);
2177			cifs_dbg(FYI, "Session needs reconnect\n");
2178
2179			mutex_lock(&ses->session_mutex);
2180			rc = cifs_negotiate_protocol(xid, ses, server);
2181			if (rc) {
2182				mutex_unlock(&ses->session_mutex);
2183				/* problem -- put our ses reference */
2184				cifs_put_smb_ses(ses);
2185				free_xid(xid);
2186				return ERR_PTR(rc);
2187			}
2188
2189			rc = cifs_setup_session(xid, ses, server,
2190						ctx->local_nls);
2191			if (rc) {
2192				mutex_unlock(&ses->session_mutex);
2193				/* problem -- put our reference */
2194				cifs_put_smb_ses(ses);
2195				free_xid(xid);
2196				return ERR_PTR(rc);
2197			}
2198			mutex_unlock(&ses->session_mutex);
2199
2200			spin_lock(&ses->chan_lock);
2201		}
2202		spin_unlock(&ses->chan_lock);
2203
2204		/* existing SMB ses has a server reference already */
2205		cifs_put_tcp_session(server, 0);
2206		free_xid(xid);
2207		return ses;
2208	}
2209
2210	rc = -ENOMEM;
2211
2212	cifs_dbg(FYI, "Existing smb sess not found\n");
2213	ses = sesInfoAlloc();
2214	if (ses == NULL)
2215		goto get_ses_fail;
2216
2217	/* new SMB session uses our server ref */
2218	ses->server = server;
2219	if (server->dstaddr.ss_family == AF_INET6)
2220		sprintf(ses->ip_addr, "%pI6", &addr6->sin6_addr);
2221	else
2222		sprintf(ses->ip_addr, "%pI4", &addr->sin_addr);
2223
2224	if (ctx->username) {
2225		ses->user_name = kstrdup(ctx->username, GFP_KERNEL);
2226		if (!ses->user_name)
2227			goto get_ses_fail;
2228	}
2229
2230	/* ctx->password freed at unmount */
2231	if (ctx->password) {
2232		ses->password = kstrdup(ctx->password, GFP_KERNEL);
2233		if (!ses->password)
2234			goto get_ses_fail;
2235	}
2236	if (ctx->domainname) {
2237		ses->domainName = kstrdup(ctx->domainname, GFP_KERNEL);
2238		if (!ses->domainName)
2239			goto get_ses_fail;
2240	}
 
 
2241
2242	strscpy(ses->workstation_name, ctx->workstation_name, sizeof(ses->workstation_name));
2243
2244	if (ctx->domainauto)
2245		ses->domainAuto = ctx->domainauto;
2246	ses->cred_uid = ctx->cred_uid;
2247	ses->linux_uid = ctx->linux_uid;
2248
2249	ses->sectype = ctx->sectype;
2250	ses->sign = ctx->sign;
2251
2252	/* add server as first channel */
2253	spin_lock(&ses->chan_lock);
2254	ses->chans[0].server = server;
2255	ses->chan_count = 1;
2256	ses->chan_max = ctx->multichannel ? ctx->max_channels:1;
2257	ses->chans_need_reconnect = 1;
2258	spin_unlock(&ses->chan_lock);
2259
2260	mutex_lock(&ses->session_mutex);
2261	rc = cifs_negotiate_protocol(xid, ses, server);
2262	if (!rc)
2263		rc = cifs_setup_session(xid, ses, server, ctx->local_nls);
2264	mutex_unlock(&ses->session_mutex);
2265
2266	/* each channel uses a different signing key */
2267	spin_lock(&ses->chan_lock);
2268	memcpy(ses->chans[0].signkey, ses->smb3signingkey,
2269	       sizeof(ses->smb3signingkey));
2270	spin_unlock(&ses->chan_lock);
2271
2272	if (rc)
2273		goto get_ses_fail;
2274
2275	/*
2276	 * success, put it on the list and add it as first channel
2277	 * note: the session becomes active soon after this. So you'll
2278	 * need to lock before changing something in the session.
2279	 */
2280	spin_lock(&cifs_tcp_ses_lock);
2281	list_add(&ses->smb_ses_list, &server->smb_ses_list);
2282	spin_unlock(&cifs_tcp_ses_lock);
2283
2284	cifs_setup_ipc(ses, ctx);
2285
2286	free_xid(xid);
2287
2288	return ses;
2289
2290get_ses_fail:
2291	sesInfoFree(ses);
2292	free_xid(xid);
2293	return ERR_PTR(rc);
2294}
2295
2296/* this function must be called with tc_lock held */
2297static int match_tcon(struct cifs_tcon *tcon, struct smb3_fs_context *ctx, bool dfs_super_cmp)
2298{
2299	if (tcon->status == TID_EXITING)
2300		return 0;
2301	/* Skip UNC validation when matching DFS superblocks */
2302	if (!dfs_super_cmp && strncmp(tcon->tree_name, ctx->UNC, MAX_TREE_SIZE))
2303		return 0;
2304	if (tcon->seal != ctx->seal)
2305		return 0;
2306	if (tcon->snapshot_time != ctx->snapshot_time)
2307		return 0;
2308	if (tcon->handle_timeout != ctx->handle_timeout)
2309		return 0;
2310	if (tcon->no_lease != ctx->no_lease)
2311		return 0;
2312	if (tcon->nodelete != ctx->nodelete)
2313		return 0;
2314	return 1;
2315}
2316
2317static struct cifs_tcon *
2318cifs_find_tcon(struct cifs_ses *ses, struct smb3_fs_context *ctx)
2319{
 
2320	struct cifs_tcon *tcon;
2321
2322	spin_lock(&cifs_tcp_ses_lock);
2323	list_for_each_entry(tcon, &ses->tcon_list, tcon_list) {
2324		spin_lock(&tcon->tc_lock);
2325		if (!match_tcon(tcon, ctx, false)) {
2326			spin_unlock(&tcon->tc_lock);
2327			continue;
2328		}
2329		++tcon->tc_count;
2330		spin_unlock(&tcon->tc_lock);
2331		spin_unlock(&cifs_tcp_ses_lock);
2332		return tcon;
2333	}
2334	spin_unlock(&cifs_tcp_ses_lock);
2335	return NULL;
2336}
2337
2338void
2339cifs_put_tcon(struct cifs_tcon *tcon)
2340{
2341	unsigned int xid;
2342	struct cifs_ses *ses;
2343
2344	/*
2345	 * IPC tcon share the lifetime of their session and are
2346	 * destroyed in the session put function
2347	 */
2348	if (tcon == NULL || tcon->ipc)
2349		return;
2350
2351	ses = tcon->ses;
2352	cifs_dbg(FYI, "%s: tc_count=%d\n", __func__, tcon->tc_count);
2353	spin_lock(&cifs_tcp_ses_lock);
2354	spin_lock(&tcon->tc_lock);
2355	if (--tcon->tc_count > 0) {
2356		spin_unlock(&tcon->tc_lock);
2357		spin_unlock(&cifs_tcp_ses_lock);
2358		return;
2359	}
2360
2361	/* tc_count can never go negative */
2362	WARN_ON(tcon->tc_count < 0);
2363
2364	list_del_init(&tcon->tcon_list);
2365	spin_unlock(&tcon->tc_lock);
2366	spin_unlock(&cifs_tcp_ses_lock);
2367
2368	/* cancel polling of interfaces */
2369	cancel_delayed_work_sync(&tcon->query_interfaces);
2370
2371	if (tcon->use_witness) {
2372		int rc;
2373
2374		rc = cifs_swn_unregister(tcon);
2375		if (rc < 0) {
2376			cifs_dbg(VFS, "%s: Failed to unregister for witness notifications: %d\n",
2377					__func__, rc);
2378		}
2379	}
2380
2381	xid = get_xid();
2382	if (ses->server->ops->tree_disconnect)
2383		ses->server->ops->tree_disconnect(xid, tcon);
2384	_free_xid(xid);
2385
2386	cifs_fscache_release_super_cookie(tcon);
2387	tconInfoFree(tcon);
2388	cifs_put_smb_ses(ses);
2389}
2390
2391/**
2392 * cifs_get_tcon - get a tcon matching @ctx data from @ses
2393 * @ses: smb session to issue the request on
2394 * @ctx: the superblock configuration context to use for building the
2395 *
2396 * - tcon refcount is the number of mount points using the tcon.
2397 * - ses refcount is the number of tcon using the session.
2398 *
2399 * 1. This function assumes it is being called from cifs_mount() where
2400 *    we already got a session reference (ses refcount +1).
2401 *
2402 * 2. Since we're in the context of adding a mount point, the end
2403 *    result should be either:
2404 *
2405 * a) a new tcon already allocated with refcount=1 (1 mount point) and
2406 *    its session refcount incremented (1 new tcon). This +1 was
2407 *    already done in (1).
2408 *
2409 * b) an existing tcon with refcount+1 (add a mount point to it) and
2410 *    identical ses refcount (no new tcon). Because of (1) we need to
2411 *    decrement the ses refcount.
2412 */
2413static struct cifs_tcon *
2414cifs_get_tcon(struct cifs_ses *ses, struct smb3_fs_context *ctx)
2415{
2416	int rc, xid;
2417	struct cifs_tcon *tcon;
2418
2419	tcon = cifs_find_tcon(ses, ctx);
2420	if (tcon) {
2421		/*
2422		 * tcon has refcount already incremented but we need to
2423		 * decrement extra ses reference gotten by caller (case b)
2424		 */
2425		cifs_dbg(FYI, "Found match on UNC path\n");
2426		cifs_put_smb_ses(ses);
 
 
 
2427		return tcon;
2428	}
2429
2430	if (!ses->server->ops->tree_connect) {
2431		rc = -ENOSYS;
2432		goto out_fail;
2433	}
2434
2435	tcon = tconInfoAlloc();
2436	if (tcon == NULL) {
2437		rc = -ENOMEM;
2438		goto out_fail;
2439	}
2440
2441	if (ctx->snapshot_time) {
2442		if (ses->server->vals->protocol_id == 0) {
2443			cifs_dbg(VFS,
2444			     "Use SMB2 or later for snapshot mount option\n");
2445			rc = -EOPNOTSUPP;
2446			goto out_fail;
2447		} else
2448			tcon->snapshot_time = ctx->snapshot_time;
2449	}
2450
2451	if (ctx->handle_timeout) {
2452		if (ses->server->vals->protocol_id == 0) {
2453			cifs_dbg(VFS,
2454			     "Use SMB2.1 or later for handle timeout option\n");
2455			rc = -EOPNOTSUPP;
2456			goto out_fail;
2457		} else
2458			tcon->handle_timeout = ctx->handle_timeout;
2459	}
2460
2461	tcon->ses = ses;
2462	if (ctx->password) {
2463		tcon->password = kstrdup(ctx->password, GFP_KERNEL);
2464		if (!tcon->password) {
2465			rc = -ENOMEM;
2466			goto out_fail;
2467		}
2468	}
2469
2470	if (ctx->seal) {
2471		if (ses->server->vals->protocol_id == 0) {
2472			cifs_dbg(VFS,
2473				 "SMB3 or later required for encryption\n");
2474			rc = -EOPNOTSUPP;
2475			goto out_fail;
2476		} else if (tcon->ses->server->capabilities &
2477					SMB2_GLOBAL_CAP_ENCRYPTION)
2478			tcon->seal = true;
2479		else {
2480			cifs_dbg(VFS, "Encryption is not supported on share\n");
2481			rc = -EOPNOTSUPP;
2482			goto out_fail;
2483		}
2484	}
2485
2486	if (ctx->linux_ext) {
2487		if (ses->server->posix_ext_supported) {
2488			tcon->posix_extensions = true;
2489			pr_warn_once("SMB3.11 POSIX Extensions are experimental\n");
2490		} else if ((ses->server->vals->protocol_id == SMB311_PROT_ID) ||
2491		    (strcmp(ses->server->vals->version_string,
2492		     SMB3ANY_VERSION_STRING) == 0) ||
2493		    (strcmp(ses->server->vals->version_string,
2494		     SMBDEFAULT_VERSION_STRING) == 0)) {
2495			cifs_dbg(VFS, "Server does not support mounting with posix SMB3.11 extensions\n");
2496			rc = -EOPNOTSUPP;
2497			goto out_fail;
2498		} else {
2499			cifs_dbg(VFS, "Check vers= mount option. SMB3.11 "
2500				"disabled but required for POSIX extensions\n");
2501			rc = -EOPNOTSUPP;
2502			goto out_fail;
2503		}
2504	}
2505
2506	xid = get_xid();
2507	rc = ses->server->ops->tree_connect(xid, ses, ctx->UNC, tcon,
2508					    ctx->local_nls);
2509	free_xid(xid);
2510	cifs_dbg(FYI, "Tcon rc = %d\n", rc);
2511	if (rc)
2512		goto out_fail;
2513
2514	tcon->use_persistent = false;
2515	/* check if SMB2 or later, CIFS does not support persistent handles */
2516	if (ctx->persistent) {
2517		if (ses->server->vals->protocol_id == 0) {
2518			cifs_dbg(VFS,
2519			     "SMB3 or later required for persistent handles\n");
2520			rc = -EOPNOTSUPP;
2521			goto out_fail;
2522		} else if (ses->server->capabilities &
2523			   SMB2_GLOBAL_CAP_PERSISTENT_HANDLES)
2524			tcon->use_persistent = true;
2525		else /* persistent handles requested but not supported */ {
2526			cifs_dbg(VFS,
2527				"Persistent handles not supported on share\n");
2528			rc = -EOPNOTSUPP;
2529			goto out_fail;
2530		}
2531	} else if ((tcon->capabilities & SMB2_SHARE_CAP_CONTINUOUS_AVAILABILITY)
2532	     && (ses->server->capabilities & SMB2_GLOBAL_CAP_PERSISTENT_HANDLES)
2533	     && (ctx->nopersistent == false)) {
2534		cifs_dbg(FYI, "enabling persistent handles\n");
2535		tcon->use_persistent = true;
2536	} else if (ctx->resilient) {
2537		if (ses->server->vals->protocol_id == 0) {
2538			cifs_dbg(VFS,
2539			     "SMB2.1 or later required for resilient handles\n");
2540			rc = -EOPNOTSUPP;
2541			goto out_fail;
2542		}
2543		tcon->use_resilient = true;
2544	}
2545
2546	tcon->use_witness = false;
2547	if (IS_ENABLED(CONFIG_CIFS_SWN_UPCALL) && ctx->witness) {
2548		if (ses->server->vals->protocol_id >= SMB30_PROT_ID) {
2549			if (tcon->capabilities & SMB2_SHARE_CAP_CLUSTER) {
2550				/*
2551				 * Set witness in use flag in first place
2552				 * to retry registration in the echo task
2553				 */
2554				tcon->use_witness = true;
2555				/* And try to register immediately */
2556				rc = cifs_swn_register(tcon);
2557				if (rc < 0) {
2558					cifs_dbg(VFS, "Failed to register for witness notifications: %d\n", rc);
2559					goto out_fail;
2560				}
2561			} else {
2562				/* TODO: try to extend for non-cluster uses (eg multichannel) */
2563				cifs_dbg(VFS, "witness requested on mount but no CLUSTER capability on share\n");
2564				rc = -EOPNOTSUPP;
2565				goto out_fail;
2566			}
2567		} else {
2568			cifs_dbg(VFS, "SMB3 or later required for witness option\n");
2569			rc = -EOPNOTSUPP;
2570			goto out_fail;
2571		}
2572	}
2573
2574	/* If the user really knows what they are doing they can override */
2575	if (tcon->share_flags & SMB2_SHAREFLAG_NO_CACHING) {
2576		if (ctx->cache_ro)
2577			cifs_dbg(VFS, "cache=ro requested on mount but NO_CACHING flag set on share\n");
2578		else if (ctx->cache_rw)
2579			cifs_dbg(VFS, "cache=singleclient requested on mount but NO_CACHING flag set on share\n");
2580	}
2581
2582	if (ctx->no_lease) {
2583		if (ses->server->vals->protocol_id == 0) {
2584			cifs_dbg(VFS,
2585				"SMB2 or later required for nolease option\n");
2586			rc = -EOPNOTSUPP;
2587			goto out_fail;
2588		} else
2589			tcon->no_lease = ctx->no_lease;
2590	}
2591
2592	/*
2593	 * We can have only one retry value for a connection to a share so for
2594	 * resources mounted more than once to the same server share the last
2595	 * value passed in for the retry flag is used.
2596	 */
2597	tcon->retry = ctx->retry;
2598	tcon->nocase = ctx->nocase;
2599	tcon->broken_sparse_sup = ctx->no_sparse;
2600	if (ses->server->capabilities & SMB2_GLOBAL_CAP_DIRECTORY_LEASING)
2601		tcon->nohandlecache = ctx->nohandlecache;
2602	else
2603		tcon->nohandlecache = true;
2604	tcon->nodelete = ctx->nodelete;
2605	tcon->local_lease = ctx->local_lease;
2606	INIT_LIST_HEAD(&tcon->pending_opens);
2607	tcon->status = TID_GOOD;
2608
2609	INIT_DELAYED_WORK(&tcon->query_interfaces,
2610			  smb2_query_server_interfaces);
2611	if (ses->server->dialect >= SMB30_PROT_ID &&
2612	    (ses->server->capabilities & SMB2_GLOBAL_CAP_MULTI_CHANNEL)) {
2613		/* schedule query interfaces poll */
2614		queue_delayed_work(cifsiod_wq, &tcon->query_interfaces,
2615				   (SMB_INTERFACE_POLL_INTERVAL * HZ));
2616	}
2617
2618	spin_lock(&cifs_tcp_ses_lock);
2619	list_add(&tcon->tcon_list, &ses->tcon_list);
2620	spin_unlock(&cifs_tcp_ses_lock);
2621
 
 
2622	return tcon;
2623
2624out_fail:
2625	tconInfoFree(tcon);
2626	return ERR_PTR(rc);
2627}
2628
2629void
2630cifs_put_tlink(struct tcon_link *tlink)
2631{
2632	if (!tlink || IS_ERR(tlink))
2633		return;
2634
2635	if (!atomic_dec_and_test(&tlink->tl_count) ||
2636	    test_bit(TCON_LINK_IN_TREE, &tlink->tl_flags)) {
2637		tlink->tl_time = jiffies;
2638		return;
2639	}
2640
2641	if (!IS_ERR(tlink_tcon(tlink)))
2642		cifs_put_tcon(tlink_tcon(tlink));
2643	kfree(tlink);
2644	return;
2645}
2646
 
 
 
 
 
 
2647static int
2648compare_mount_options(struct super_block *sb, struct cifs_mnt_data *mnt_data)
2649{
2650	struct cifs_sb_info *old = CIFS_SB(sb);
2651	struct cifs_sb_info *new = mnt_data->cifs_sb;
2652	unsigned int oldflags = old->mnt_cifs_flags & CIFS_MOUNT_MASK;
2653	unsigned int newflags = new->mnt_cifs_flags & CIFS_MOUNT_MASK;
2654
2655	if ((sb->s_flags & CIFS_MS_MASK) != (mnt_data->flags & CIFS_MS_MASK))
2656		return 0;
2657
2658	if (old->mnt_cifs_serverino_autodisabled)
2659		newflags &= ~CIFS_MOUNT_SERVER_INUM;
 
2660
2661	if (oldflags != newflags)
2662		return 0;
2663
2664	/*
2665	 * We want to share sb only if we don't specify an r/wsize or
2666	 * specified r/wsize is greater than or equal to existing one.
2667	 */
2668	if (new->ctx->wsize && new->ctx->wsize < old->ctx->wsize)
2669		return 0;
2670
2671	if (new->ctx->rsize && new->ctx->rsize < old->ctx->rsize)
2672		return 0;
2673
2674	if (!uid_eq(old->ctx->linux_uid, new->ctx->linux_uid) ||
2675	    !gid_eq(old->ctx->linux_gid, new->ctx->linux_gid))
2676		return 0;
2677
2678	if (old->ctx->file_mode != new->ctx->file_mode ||
2679	    old->ctx->dir_mode != new->ctx->dir_mode)
2680		return 0;
2681
2682	if (strcmp(old->local_nls->charset, new->local_nls->charset))
2683		return 0;
2684
2685	if (old->ctx->acregmax != new->ctx->acregmax)
2686		return 0;
2687	if (old->ctx->acdirmax != new->ctx->acdirmax)
2688		return 0;
2689	if (old->ctx->closetimeo != new->ctx->closetimeo)
2690		return 0;
2691
2692	return 1;
2693}
2694
2695static int
2696match_prepath(struct super_block *sb, struct cifs_mnt_data *mnt_data)
2697{
2698	struct cifs_sb_info *old = CIFS_SB(sb);
2699	struct cifs_sb_info *new = mnt_data->cifs_sb;
2700	bool old_set = (old->mnt_cifs_flags & CIFS_MOUNT_USE_PREFIX_PATH) &&
2701		old->prepath;
2702	bool new_set = (new->mnt_cifs_flags & CIFS_MOUNT_USE_PREFIX_PATH) &&
2703		new->prepath;
2704
2705	if (old_set && new_set && !strcmp(new->prepath, old->prepath))
2706		return 1;
2707	else if (!old_set && !new_set)
2708		return 1;
2709
2710	return 0;
2711}
2712
2713int
2714cifs_match_super(struct super_block *sb, void *data)
2715{
2716	struct cifs_mnt_data *mnt_data = data;
2717	struct smb3_fs_context *ctx;
2718	struct cifs_sb_info *cifs_sb;
2719	struct TCP_Server_Info *tcp_srv;
2720	struct cifs_ses *ses;
2721	struct cifs_tcon *tcon;
2722	struct tcon_link *tlink;
2723	bool dfs_super_cmp;
2724	int rc = 0;
2725
 
 
2726	spin_lock(&cifs_tcp_ses_lock);
2727	cifs_sb = CIFS_SB(sb);
2728	tlink = cifs_get_tlink(cifs_sb_master_tlink(cifs_sb));
2729	if (tlink == NULL) {
2730		/* can not match superblock if tlink were ever null */
2731		spin_unlock(&cifs_tcp_ses_lock);
2732		return 0;
2733	}
2734	tcon = tlink_tcon(tlink);
2735	ses = tcon->ses;
2736	tcp_srv = ses->server;
2737
2738	dfs_super_cmp = IS_ENABLED(CONFIG_CIFS_DFS_UPCALL) && tcp_srv->origin_fullpath;
 
 
 
2739
2740	ctx = mnt_data->ctx;
 
 
 
 
 
2741
2742	spin_lock(&tcp_srv->srv_lock);
2743	spin_lock(&ses->ses_lock);
2744	spin_lock(&tcon->tc_lock);
2745	if (!match_server(tcp_srv, ctx, dfs_super_cmp) ||
2746	    !match_session(ses, ctx) ||
2747	    !match_tcon(tcon, ctx, dfs_super_cmp) ||
2748	    !match_prepath(sb, mnt_data)) {
2749		rc = 0;
2750		goto out;
2751	}
2752
2753	rc = compare_mount_options(sb, mnt_data);
2754out:
2755	spin_unlock(&tcon->tc_lock);
2756	spin_unlock(&ses->ses_lock);
2757	spin_unlock(&tcp_srv->srv_lock);
2758
2759	spin_unlock(&cifs_tcp_ses_lock);
2760	cifs_put_tlink(tlink);
2761	return rc;
2762}
2763
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
2764#ifdef CONFIG_DEBUG_LOCK_ALLOC
2765static struct lock_class_key cifs_key[2];
2766static struct lock_class_key cifs_slock_key[2];
2767
2768static inline void
2769cifs_reclassify_socket4(struct socket *sock)
2770{
2771	struct sock *sk = sock->sk;
2772	BUG_ON(!sock_allow_reclassification(sk));
2773	sock_lock_init_class_and_name(sk, "slock-AF_INET-CIFS",
2774		&cifs_slock_key[0], "sk_lock-AF_INET-CIFS", &cifs_key[0]);
2775}
2776
2777static inline void
2778cifs_reclassify_socket6(struct socket *sock)
2779{
2780	struct sock *sk = sock->sk;
2781	BUG_ON(!sock_allow_reclassification(sk));
2782	sock_lock_init_class_and_name(sk, "slock-AF_INET6-CIFS",
2783		&cifs_slock_key[1], "sk_lock-AF_INET6-CIFS", &cifs_key[1]);
2784}
2785#else
2786static inline void
2787cifs_reclassify_socket4(struct socket *sock)
2788{
2789}
2790
2791static inline void
2792cifs_reclassify_socket6(struct socket *sock)
2793{
2794}
2795#endif
2796
2797/* See RFC1001 section 14 on representation of Netbios names */
2798static void rfc1002mangle(char *target, char *source, unsigned int length)
2799{
2800	unsigned int i, j;
2801
2802	for (i = 0, j = 0; i < (length); i++) {
2803		/* mask a nibble at a time and encode */
2804		target[j] = 'A' + (0x0F & (source[i] >> 4));
2805		target[j+1] = 'A' + (0x0F & source[i]);
2806		j += 2;
2807	}
2808
2809}
2810
2811static int
2812bind_socket(struct TCP_Server_Info *server)
2813{
2814	int rc = 0;
2815	if (server->srcaddr.ss_family != AF_UNSPEC) {
2816		/* Bind to the specified local IP address */
2817		struct socket *socket = server->ssocket;
2818		rc = socket->ops->bind(socket,
2819				       (struct sockaddr *) &server->srcaddr,
2820				       sizeof(server->srcaddr));
2821		if (rc < 0) {
2822			struct sockaddr_in *saddr4;
2823			struct sockaddr_in6 *saddr6;
2824			saddr4 = (struct sockaddr_in *)&server->srcaddr;
2825			saddr6 = (struct sockaddr_in6 *)&server->srcaddr;
2826			if (saddr6->sin6_family == AF_INET6)
2827				cifs_server_dbg(VFS, "Failed to bind to: %pI6c, error: %d\n",
2828					 &saddr6->sin6_addr, rc);
 
2829			else
2830				cifs_server_dbg(VFS, "Failed to bind to: %pI4, error: %d\n",
2831					 &saddr4->sin_addr.s_addr, rc);
 
2832		}
2833	}
2834	return rc;
2835}
2836
2837static int
2838ip_rfc1001_connect(struct TCP_Server_Info *server)
2839{
2840	int rc = 0;
2841	/*
2842	 * some servers require RFC1001 sessinit before sending
2843	 * negprot - BB check reconnection in case where second
2844	 * sessinit is sent but no second negprot
2845	 */
2846	struct rfc1002_session_packet *ses_init_buf;
2847	unsigned int req_noscope_len;
2848	struct smb_hdr *smb_buf;
2849
2850	ses_init_buf = kzalloc(sizeof(struct rfc1002_session_packet),
2851			       GFP_KERNEL);
2852
2853	if (ses_init_buf) {
2854		ses_init_buf->trailer.session_req.called_len = 32;
2855
2856		if (server->server_RFC1001_name[0] != 0)
 
2857			rfc1002mangle(ses_init_buf->trailer.
2858				      session_req.called_name,
2859				      server->server_RFC1001_name,
2860				      RFC1001_NAME_LEN_WITH_NULL);
2861		else
2862			rfc1002mangle(ses_init_buf->trailer.
2863				      session_req.called_name,
2864				      DEFAULT_CIFS_CALLED_NAME,
2865				      RFC1001_NAME_LEN_WITH_NULL);
2866
2867		ses_init_buf->trailer.session_req.calling_len = 32;
2868
2869		/*
2870		 * calling name ends in null (byte 16) from old smb
2871		 * convention.
2872		 */
2873		if (server->workstation_RFC1001_name[0] != 0)
 
2874			rfc1002mangle(ses_init_buf->trailer.
2875				      session_req.calling_name,
2876				      server->workstation_RFC1001_name,
2877				      RFC1001_NAME_LEN_WITH_NULL);
2878		else
2879			rfc1002mangle(ses_init_buf->trailer.
2880				      session_req.calling_name,
2881				      "LINUX_CIFS_CLNT",
2882				      RFC1001_NAME_LEN_WITH_NULL);
2883
2884		ses_init_buf->trailer.session_req.scope1 = 0;
2885		ses_init_buf->trailer.session_req.scope2 = 0;
2886		smb_buf = (struct smb_hdr *)ses_init_buf;
2887
2888		/* sizeof RFC1002_SESSION_REQUEST with no scopes */
2889		req_noscope_len = sizeof(struct rfc1002_session_packet) - 2;
2890
2891		/* == cpu_to_be32(0x81000044) */
2892		smb_buf->smb_buf_length =
2893			cpu_to_be32((RFC1002_SESSION_REQUEST << 24) | req_noscope_len);
2894		rc = smb_send(server, smb_buf, 0x44);
2895		kfree(ses_init_buf);
2896		/*
2897		 * RFC1001 layer in at least one server
2898		 * requires very short break before negprot
2899		 * presumably because not expecting negprot
2900		 * to follow so fast.  This is a simple
2901		 * solution that works without
2902		 * complicating the code and causes no
2903		 * significant slowing down on mount
2904		 * for everyone else
2905		 */
2906		usleep_range(1000, 2000);
2907	}
2908	/*
2909	 * else the negprot may still work without this
2910	 * even though malloc failed
2911	 */
2912
2913	return rc;
2914}
2915
2916static int
2917generic_ip_connect(struct TCP_Server_Info *server)
2918{
2919	int rc = 0;
2920	__be16 sport;
2921	int slen, sfamily;
2922	struct socket *socket = server->ssocket;
2923	struct sockaddr *saddr;
2924
2925	saddr = (struct sockaddr *) &server->dstaddr;
2926
2927	if (server->dstaddr.ss_family == AF_INET6) {
2928		struct sockaddr_in6 *ipv6 = (struct sockaddr_in6 *)&server->dstaddr;
2929
2930		sport = ipv6->sin6_port;
2931		slen = sizeof(struct sockaddr_in6);
2932		sfamily = AF_INET6;
2933		cifs_dbg(FYI, "%s: connecting to [%pI6]:%d\n", __func__, &ipv6->sin6_addr,
2934				ntohs(sport));
2935	} else {
2936		struct sockaddr_in *ipv4 = (struct sockaddr_in *)&server->dstaddr;
2937
2938		sport = ipv4->sin_port;
2939		slen = sizeof(struct sockaddr_in);
2940		sfamily = AF_INET;
2941		cifs_dbg(FYI, "%s: connecting to %pI4:%d\n", __func__, &ipv4->sin_addr,
2942				ntohs(sport));
2943	}
2944
2945	if (socket == NULL) {
2946		rc = __sock_create(cifs_net_ns(server), sfamily, SOCK_STREAM,
2947				   IPPROTO_TCP, &socket, 1);
2948		if (rc < 0) {
2949			cifs_server_dbg(VFS, "Error %d creating socket\n", rc);
2950			server->ssocket = NULL;
2951			return rc;
2952		}
2953
2954		/* BB other socket options to set KEEPALIVE, NODELAY? */
2955		cifs_dbg(FYI, "Socket created\n");
2956		server->ssocket = socket;
2957		socket->sk->sk_allocation = GFP_NOFS;
2958		socket->sk->sk_use_task_frag = false;
2959		if (sfamily == AF_INET6)
2960			cifs_reclassify_socket6(socket);
2961		else
2962			cifs_reclassify_socket4(socket);
2963	}
2964
2965	rc = bind_socket(server);
2966	if (rc < 0)
2967		return rc;
2968
2969	/*
2970	 * Eventually check for other socket options to change from
2971	 * the default. sock_setsockopt not used because it expects
2972	 * user space buffer
2973	 */
2974	socket->sk->sk_rcvtimeo = 7 * HZ;
2975	socket->sk->sk_sndtimeo = 5 * HZ;
2976
2977	/* make the bufsizes depend on wsize/rsize and max requests */
2978	if (server->noautotune) {
2979		if (socket->sk->sk_sndbuf < (200 * 1024))
2980			socket->sk->sk_sndbuf = 200 * 1024;
2981		if (socket->sk->sk_rcvbuf < (140 * 1024))
2982			socket->sk->sk_rcvbuf = 140 * 1024;
2983	}
2984
2985	if (server->tcp_nodelay)
2986		tcp_sock_set_nodelay(socket->sk);
 
 
 
 
 
2987
2988	cifs_dbg(FYI, "sndbuf %d rcvbuf %d rcvtimeo 0x%lx\n",
2989		 socket->sk->sk_sndbuf,
2990		 socket->sk->sk_rcvbuf, socket->sk->sk_rcvtimeo);
2991
2992	rc = socket->ops->connect(socket, saddr, slen,
2993				  server->noblockcnt ? O_NONBLOCK : 0);
2994	/*
2995	 * When mounting SMB root file systems, we do not want to block in
2996	 * connect. Otherwise bail out and then let cifs_reconnect() perform
2997	 * reconnect failover - if possible.
2998	 */
2999	if (server->noblockcnt && rc == -EINPROGRESS)
3000		rc = 0;
3001	if (rc < 0) {
3002		cifs_dbg(FYI, "Error %d connecting to server\n", rc);
3003		trace_smb3_connect_err(server->hostname, server->conn_id, &server->dstaddr, rc);
3004		sock_release(socket);
3005		server->ssocket = NULL;
3006		return rc;
3007	}
3008	trace_smb3_connect_done(server->hostname, server->conn_id, &server->dstaddr);
3009	if (sport == htons(RFC1001_PORT))
3010		rc = ip_rfc1001_connect(server);
3011
3012	return rc;
3013}
3014
3015static int
3016ip_connect(struct TCP_Server_Info *server)
3017{
3018	__be16 *sport;
3019	struct sockaddr_in6 *addr6 = (struct sockaddr_in6 *)&server->dstaddr;
3020	struct sockaddr_in *addr = (struct sockaddr_in *)&server->dstaddr;
3021
3022	if (server->dstaddr.ss_family == AF_INET6)
3023		sport = &addr6->sin6_port;
3024	else
3025		sport = &addr->sin_port;
3026
3027	if (*sport == 0) {
3028		int rc;
3029
3030		/* try with 445 port at first */
3031		*sport = htons(CIFS_PORT);
3032
3033		rc = generic_ip_connect(server);
3034		if (rc >= 0)
3035			return rc;
3036
3037		/* if it failed, try with 139 port */
3038		*sport = htons(RFC1001_PORT);
3039	}
3040
3041	return generic_ip_connect(server);
3042}
3043
3044#ifdef CONFIG_CIFS_ALLOW_INSECURE_LEGACY
3045void reset_cifs_unix_caps(unsigned int xid, struct cifs_tcon *tcon,
3046			  struct cifs_sb_info *cifs_sb, struct smb3_fs_context *ctx)
3047{
3048	/*
3049	 * If we are reconnecting then should we check to see if
3050	 * any requested capabilities changed locally e.g. via
3051	 * remount but we can not do much about it here
3052	 * if they have (even if we could detect it by the following)
3053	 * Perhaps we could add a backpointer to array of sb from tcon
3054	 * or if we change to make all sb to same share the same
3055	 * sb as NFS - then we only have one backpointer to sb.
3056	 * What if we wanted to mount the server share twice once with
3057	 * and once without posixacls or posix paths?
3058	 */
3059	__u64 saved_cap = le64_to_cpu(tcon->fsUnixInfo.Capability);
3060
3061	if (ctx && ctx->no_linux_ext) {
3062		tcon->fsUnixInfo.Capability = 0;
3063		tcon->unix_ext = 0; /* Unix Extensions disabled */
3064		cifs_dbg(FYI, "Linux protocol extensions disabled\n");
3065		return;
3066	} else if (ctx)
3067		tcon->unix_ext = 1; /* Unix Extensions supported */
3068
3069	if (!tcon->unix_ext) {
3070		cifs_dbg(FYI, "Unix extensions disabled so not set on reconnect\n");
3071		return;
3072	}
3073
3074	if (!CIFSSMBQFSUnixInfo(xid, tcon)) {
3075		__u64 cap = le64_to_cpu(tcon->fsUnixInfo.Capability);
3076		cifs_dbg(FYI, "unix caps which server supports %lld\n", cap);
3077		/*
3078		 * check for reconnect case in which we do not
3079		 * want to change the mount behavior if we can avoid it
3080		 */
3081		if (ctx == NULL) {
3082			/*
3083			 * turn off POSIX ACL and PATHNAMES if not set
3084			 * originally at mount time
3085			 */
3086			if ((saved_cap & CIFS_UNIX_POSIX_ACL_CAP) == 0)
3087				cap &= ~CIFS_UNIX_POSIX_ACL_CAP;
3088			if ((saved_cap & CIFS_UNIX_POSIX_PATHNAMES_CAP) == 0) {
3089				if (cap & CIFS_UNIX_POSIX_PATHNAMES_CAP)
3090					cifs_dbg(VFS, "POSIXPATH support change\n");
3091				cap &= ~CIFS_UNIX_POSIX_PATHNAMES_CAP;
3092			} else if ((cap & CIFS_UNIX_POSIX_PATHNAMES_CAP) == 0) {
3093				cifs_dbg(VFS, "possible reconnect error\n");
3094				cifs_dbg(VFS, "server disabled POSIX path support\n");
3095			}
3096		}
3097
3098		if (cap & CIFS_UNIX_TRANSPORT_ENCRYPTION_MANDATORY_CAP)
3099			cifs_dbg(VFS, "per-share encryption not supported yet\n");
3100
3101		cap &= CIFS_UNIX_CAP_MASK;
3102		if (ctx && ctx->no_psx_acl)
3103			cap &= ~CIFS_UNIX_POSIX_ACL_CAP;
3104		else if (CIFS_UNIX_POSIX_ACL_CAP & cap) {
3105			cifs_dbg(FYI, "negotiated posix acl support\n");
3106			if (cifs_sb)
3107				cifs_sb->mnt_cifs_flags |=
3108					CIFS_MOUNT_POSIXACL;
3109		}
3110
3111		if (ctx && ctx->posix_paths == 0)
3112			cap &= ~CIFS_UNIX_POSIX_PATHNAMES_CAP;
3113		else if (cap & CIFS_UNIX_POSIX_PATHNAMES_CAP) {
3114			cifs_dbg(FYI, "negotiate posix pathnames\n");
3115			if (cifs_sb)
3116				cifs_sb->mnt_cifs_flags |=
3117					CIFS_MOUNT_POSIX_PATHS;
3118		}
3119
3120		cifs_dbg(FYI, "Negotiate caps 0x%x\n", (int)cap);
 
 
 
 
 
 
 
 
3121#ifdef CONFIG_CIFS_DEBUG2
3122		if (cap & CIFS_UNIX_FCNTL_CAP)
3123			cifs_dbg(FYI, "FCNTL cap\n");
3124		if (cap & CIFS_UNIX_EXTATTR_CAP)
3125			cifs_dbg(FYI, "EXTATTR cap\n");
3126		if (cap & CIFS_UNIX_POSIX_PATHNAMES_CAP)
3127			cifs_dbg(FYI, "POSIX path cap\n");
3128		if (cap & CIFS_UNIX_XATTR_CAP)
3129			cifs_dbg(FYI, "XATTR cap\n");
3130		if (cap & CIFS_UNIX_POSIX_ACL_CAP)
3131			cifs_dbg(FYI, "POSIX ACL cap\n");
3132		if (cap & CIFS_UNIX_LARGE_READ_CAP)
3133			cifs_dbg(FYI, "very large read cap\n");
3134		if (cap & CIFS_UNIX_LARGE_WRITE_CAP)
3135			cifs_dbg(FYI, "very large write cap\n");
3136		if (cap & CIFS_UNIX_TRANSPORT_ENCRYPTION_CAP)
3137			cifs_dbg(FYI, "transport encryption cap\n");
3138		if (cap & CIFS_UNIX_TRANSPORT_ENCRYPTION_MANDATORY_CAP)
3139			cifs_dbg(FYI, "mandatory transport encryption cap\n");
3140#endif /* CIFS_DEBUG2 */
3141		if (CIFSSMBSetFSUnixInfo(xid, tcon, cap)) {
3142			if (ctx == NULL)
3143				cifs_dbg(FYI, "resetting capabilities failed\n");
3144			else
3145				cifs_dbg(VFS, "Negotiating Unix capabilities with the server failed. Consider mounting with the Unix Extensions disabled if problems are found by specifying the nounix mount option.\n");
 
 
 
 
 
3146
3147		}
3148	}
3149}
3150#endif /* CONFIG_CIFS_ALLOW_INSECURE_LEGACY */
3151
3152int cifs_setup_cifs_sb(struct cifs_sb_info *cifs_sb)
 
3153{
3154	struct smb3_fs_context *ctx = cifs_sb->ctx;
3155
3156	INIT_DELAYED_WORK(&cifs_sb->prune_tlinks, cifs_prune_tlinks);
3157
3158	spin_lock_init(&cifs_sb->tlink_tree_lock);
3159	cifs_sb->tlink_tree = RB_ROOT;
3160
3161	cifs_dbg(FYI, "file mode: %04ho  dir mode: %04ho\n",
3162		 ctx->file_mode, ctx->dir_mode);
3163
3164	/* this is needed for ASCII cp to Unicode converts */
3165	if (ctx->iocharset == NULL) {
3166		/* load_nls_default cannot return null */
3167		cifs_sb->local_nls = load_nls_default();
3168	} else {
3169		cifs_sb->local_nls = load_nls(ctx->iocharset);
3170		if (cifs_sb->local_nls == NULL) {
3171			cifs_dbg(VFS, "CIFS mount error: iocharset %s not found\n",
3172				 ctx->iocharset);
3173			return -ELIBACC;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3174		}
3175	}
3176	ctx->local_nls = cifs_sb->local_nls;
3177
3178	smb3_update_mnt_flags(cifs_sb);
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3179
3180	if (ctx->direct_io)
3181		cifs_dbg(FYI, "mounting share using direct i/o\n");
3182	if (ctx->cache_ro) {
3183		cifs_dbg(VFS, "mounting share with read only caching. Ensure that the share will not be modified while in use.\n");
3184		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_RO_CACHE;
3185	} else if (ctx->cache_rw) {
3186		cifs_dbg(VFS, "mounting share in single client RW caching mode. Ensure that no other systems will be accessing the share.\n");
3187		cifs_sb->mnt_cifs_flags |= (CIFS_MOUNT_RO_CACHE |
3188					    CIFS_MOUNT_RW_CACHE);
3189	}
3190
3191	if ((ctx->cifs_acl) && (ctx->dynperm))
3192		cifs_dbg(VFS, "mount option dynperm ignored if cifsacl mount option supported\n");
3193
3194	if (ctx->prepath) {
3195		cifs_sb->prepath = kstrdup(ctx->prepath, GFP_KERNEL);
3196		if (cifs_sb->prepath == NULL)
3197			return -ENOMEM;
3198		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_USE_PREFIX_PATH;
 
 
 
3199	}
3200
3201	return 0;
 
 
 
3202}
3203
3204/* Release all succeed connections */
3205void cifs_mount_put_conns(struct cifs_mount_ctx *mnt_ctx)
 
 
 
 
 
 
 
 
 
 
 
 
3206{
3207	int rc = 0;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3208
3209	if (mnt_ctx->tcon)
3210		cifs_put_tcon(mnt_ctx->tcon);
3211	else if (mnt_ctx->ses)
3212		cifs_put_smb_ses(mnt_ctx->ses);
3213	else if (mnt_ctx->server)
3214		cifs_put_tcp_session(mnt_ctx->server, 0);
3215	mnt_ctx->cifs_sb->mnt_cifs_flags &= ~CIFS_MOUNT_POSIX_PATHS;
3216	free_xid(mnt_ctx->xid);
3217}
3218
3219int cifs_mount_get_session(struct cifs_mount_ctx *mnt_ctx)
3220{
3221	struct TCP_Server_Info *server = NULL;
3222	struct smb3_fs_context *ctx;
3223	struct cifs_ses *ses = NULL;
3224	unsigned int xid;
3225	int rc = 0;
3226
3227	xid = get_xid();
 
3228
3229	if (WARN_ON_ONCE(!mnt_ctx || !mnt_ctx->fs_ctx)) {
3230		rc = -EINVAL;
3231		goto out;
 
 
 
 
 
 
 
 
 
 
3232	}
3233	ctx = mnt_ctx->fs_ctx;
3234
3235	/* get a reference to a tcp session */
3236	server = cifs_get_tcp_session(ctx, NULL);
3237	if (IS_ERR(server)) {
3238		rc = PTR_ERR(server);
3239		server = NULL;
3240		goto out;
 
 
 
 
 
3241	}
3242
3243	/* get a reference to a SMB session */
3244	ses = cifs_get_smb_ses(server, ctx);
3245	if (IS_ERR(ses)) {
3246		rc = PTR_ERR(ses);
3247		ses = NULL;
3248		goto out;
3249	}
 
 
 
 
 
3250
3251	if ((ctx->persistent == true) && (!(ses->server->capabilities &
3252					    SMB2_GLOBAL_CAP_PERSISTENT_HANDLES))) {
3253		cifs_server_dbg(VFS, "persistent handles not supported by server\n");
3254		rc = -EOPNOTSUPP;
3255	}
3256
3257out:
3258	mnt_ctx->xid = xid;
3259	mnt_ctx->server = server;
3260	mnt_ctx->ses = ses;
3261	mnt_ctx->tcon = NULL;
3262
3263	return rc;
3264}
3265
3266int cifs_mount_get_tcon(struct cifs_mount_ctx *mnt_ctx)
 
3267{
3268	struct TCP_Server_Info *server;
3269	struct cifs_sb_info *cifs_sb;
3270	struct smb3_fs_context *ctx;
3271	struct cifs_tcon *tcon = NULL;
3272	int rc = 0;
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3273
3274	if (WARN_ON_ONCE(!mnt_ctx || !mnt_ctx->server || !mnt_ctx->ses || !mnt_ctx->fs_ctx ||
3275			 !mnt_ctx->cifs_sb)) {
3276		rc = -EINVAL;
 
 
3277		goto out;
3278	}
3279	server = mnt_ctx->server;
3280	ctx = mnt_ctx->fs_ctx;
3281	cifs_sb = mnt_ctx->cifs_sb;
 
 
 
 
 
3282
3283	/* search for existing tcon to this server share */
3284	tcon = cifs_get_tcon(mnt_ctx->ses, ctx);
3285	if (IS_ERR(tcon)) {
3286		rc = PTR_ERR(tcon);
3287		tcon = NULL;
3288		goto out;
3289	}
3290
3291	/* if new SMB3.11 POSIX extensions are supported do not remap / and \ */
3292	if (tcon->posix_extensions)
3293		cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_POSIX_PATHS;
3294
3295#ifdef CONFIG_CIFS_ALLOW_INSECURE_LEGACY
3296	/* tell server which Unix caps we support */
3297	if (cap_unix(tcon->ses)) {
3298		/*
3299		 * reset of caps checks mount to see if unix extensions disabled
3300		 * for just this mount.
3301		 */
3302		reset_cifs_unix_caps(mnt_ctx->xid, tcon, cifs_sb, ctx);
3303		spin_lock(&tcon->ses->server->srv_lock);
3304		if ((tcon->ses->server->tcpStatus == CifsNeedReconnect) &&
3305		    (le64_to_cpu(tcon->fsUnixInfo.Capability) &
3306		     CIFS_UNIX_TRANSPORT_ENCRYPTION_MANDATORY_CAP)) {
3307			spin_unlock(&tcon->ses->server->srv_lock);
3308			rc = -EACCES;
3309			goto out;
3310		}
3311		spin_unlock(&tcon->ses->server->srv_lock);
3312	} else
3313#endif /* CONFIG_CIFS_ALLOW_INSECURE_LEGACY */
3314		tcon->unix_ext = 0; /* server does not support them */
3315
3316	/* do not care if a following call succeed - informational */
3317	if (!tcon->pipe && server->ops->qfs_tcon) {
3318		server->ops->qfs_tcon(mnt_ctx->xid, tcon, cifs_sb);
3319		if (cifs_sb->mnt_cifs_flags & CIFS_MOUNT_RO_CACHE) {
3320			if (tcon->fsDevInfo.DeviceCharacteristics &
3321			    cpu_to_le32(FILE_READ_ONLY_DEVICE))
3322				cifs_dbg(VFS, "mounted to read only share\n");
3323			else if ((cifs_sb->mnt_cifs_flags &
3324				  CIFS_MOUNT_RW_CACHE) == 0)
3325				cifs_dbg(VFS, "read only mount of RW share\n");
3326			/* no need to log a RW mount of a typical RW share */
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3327		}
3328	}
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3329
3330	/*
3331	 * Clamp the rsize/wsize mount arguments if they are too big for the server
3332	 * and set the rsize/wsize to the negotiated values if not passed in by
3333	 * the user on mount
3334	 */
3335	if ((cifs_sb->ctx->wsize == 0) ||
3336	    (cifs_sb->ctx->wsize > server->ops->negotiate_wsize(tcon, ctx)))
3337		cifs_sb->ctx->wsize = server->ops->negotiate_wsize(tcon, ctx);
3338	if ((cifs_sb->ctx->rsize == 0) ||
3339	    (cifs_sb->ctx->rsize > server->ops->negotiate_rsize(tcon, ctx)))
3340		cifs_sb->ctx->rsize = server->ops->negotiate_rsize(tcon, ctx);
 
 
3341
3342	/*
3343	 * The cookie is initialized from volume info returned above.
3344	 * Inside cifs_fscache_get_super_cookie it checks
3345	 * that we do not get super cookie twice.
3346	 */
3347	if (cifs_sb->mnt_cifs_flags & CIFS_MOUNT_FSCACHE)
3348		cifs_fscache_get_super_cookie(tcon);
3349
3350out:
3351	mnt_ctx->tcon = tcon;
3352	return rc;
3353}
 
 
 
 
 
3354
3355static int mount_setup_tlink(struct cifs_sb_info *cifs_sb, struct cifs_ses *ses,
3356			     struct cifs_tcon *tcon)
3357{
3358	struct tcon_link *tlink;
3359
3360	/* hang the tcon off of the superblock */
3361	tlink = kzalloc(sizeof(*tlink), GFP_KERNEL);
3362	if (tlink == NULL)
3363		return -ENOMEM;
 
 
3364
3365	tlink->tl_uid = ses->linux_uid;
3366	tlink->tl_tcon = tcon;
3367	tlink->tl_time = jiffies;
3368	set_bit(TCON_LINK_MASTER, &tlink->tl_flags);
3369	set_bit(TCON_LINK_IN_TREE, &tlink->tl_flags);
3370
3371	cifs_sb->master_tlink = tlink;
3372	spin_lock(&cifs_sb->tlink_tree_lock);
3373	tlink_rb_insert(&cifs_sb->tlink_tree, tlink);
3374	spin_unlock(&cifs_sb->tlink_tree_lock);
3375
3376	queue_delayed_work(cifsiod_wq, &cifs_sb->prune_tlinks,
3377				TLINK_IDLE_EXPIRE);
3378	return 0;
3379}
3380
3381static int
3382cifs_are_all_path_components_accessible(struct TCP_Server_Info *server,
3383					unsigned int xid,
3384					struct cifs_tcon *tcon,
3385					struct cifs_sb_info *cifs_sb,
3386					char *full_path,
3387					int added_treename)
3388{
3389	int rc;
3390	char *s;
3391	char sep, tmp;
3392	int skip = added_treename ? 1 : 0;
3393
3394	sep = CIFS_DIR_SEP(cifs_sb);
3395	s = full_path;
3396
3397	rc = server->ops->is_path_accessible(xid, tcon, cifs_sb, "");
3398	while (rc == 0) {
3399		/* skip separators */
3400		while (*s == sep)
3401			s++;
3402		if (!*s)
3403			break;
3404		/* next separator */
3405		while (*s && *s != sep)
3406			s++;
3407		/*
3408		 * if the treename is added, we then have to skip the first
3409		 * part within the separators
3410		 */
3411		if (skip) {
3412			skip = 0;
3413			continue;
3414		}
3415		/*
3416		 * temporarily null-terminate the path at the end of
3417		 * the current component
3418		 */
3419		tmp = *s;
3420		*s = 0;
3421		rc = server->ops->is_path_accessible(xid, tcon, cifs_sb,
3422						     full_path);
3423		*s = tmp;
3424	}
3425	return rc;
3426}
3427
3428/*
3429 * Check if path is remote (i.e. a DFS share).
3430 *
3431 * Return -EREMOTE if it is, otherwise 0 or -errno.
3432 */
3433int cifs_is_path_remote(struct cifs_mount_ctx *mnt_ctx)
3434{
3435	int rc;
3436	struct cifs_sb_info *cifs_sb = mnt_ctx->cifs_sb;
3437	struct TCP_Server_Info *server = mnt_ctx->server;
3438	unsigned int xid = mnt_ctx->xid;
3439	struct cifs_tcon *tcon = mnt_ctx->tcon;
3440	struct smb3_fs_context *ctx = mnt_ctx->fs_ctx;
3441	char *full_path;
3442
3443	if (!server->ops->is_path_accessible)
3444		return -EOPNOTSUPP;
3445
3446	/*
3447	 * cifs_build_path_to_root works only when we have a valid tcon
3448	 */
3449	full_path = cifs_build_path_to_root(ctx, cifs_sb, tcon,
3450					    tcon->Flags & SMB_SHARE_IS_IN_DFS);
3451	if (full_path == NULL)
3452		return -ENOMEM;
3453
3454	cifs_dbg(FYI, "%s: full_path: %s\n", __func__, full_path);
3455
3456	rc = server->ops->is_path_accessible(xid, tcon, cifs_sb,
3457					     full_path);
3458	if (rc != 0 && rc != -EREMOTE)
3459		goto out;
3460
3461	if (rc != -EREMOTE) {
3462		rc = cifs_are_all_path_components_accessible(server, xid, tcon,
3463			cifs_sb, full_path, tcon->Flags & SMB_SHARE_IS_IN_DFS);
3464		if (rc != 0) {
3465			cifs_server_dbg(VFS, "cannot query dirs between root and final path, enabling CIFS_MOUNT_USE_PREFIX_PATH\n");
3466			cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_USE_PREFIX_PATH;
3467			rc = 0;
3468		}
3469	}
3470
3471out:
3472	kfree(full_path);
3473	return rc;
3474}
3475
3476#ifdef CONFIG_CIFS_DFS_UPCALL
3477int cifs_mount(struct cifs_sb_info *cifs_sb, struct smb3_fs_context *ctx)
3478{
3479	struct cifs_mount_ctx mnt_ctx = { .cifs_sb = cifs_sb, .fs_ctx = ctx, };
3480	bool isdfs;
3481	int rc;
3482
3483	uuid_gen(&mnt_ctx.mount_id);
3484	rc = dfs_mount_share(&mnt_ctx, &isdfs);
3485	if (rc)
3486		goto error;
3487	if (!isdfs)
3488		goto out;
3489
3490	/*
3491	 * After reconnecting to a different server, unique ids won't match anymore, so we disable
3492	 * serverino. This prevents dentry revalidation to think the dentry are stale (ESTALE).
3493	 */
3494	cifs_autodisable_serverino(cifs_sb);
3495	/*
3496	 * Force the use of prefix path to support failover on DFS paths that resolve to targets
3497	 * that have different prefix paths.
3498	 */
3499	cifs_sb->mnt_cifs_flags |= CIFS_MOUNT_USE_PREFIX_PATH;
3500	kfree(cifs_sb->prepath);
3501	cifs_sb->prepath = ctx->prepath;
3502	ctx->prepath = NULL;
3503	uuid_copy(&cifs_sb->dfs_mount_id, &mnt_ctx.mount_id);
3504
3505out:
3506	cifs_try_adding_channels(cifs_sb, mnt_ctx.ses);
3507	rc = mount_setup_tlink(cifs_sb, mnt_ctx.ses, mnt_ctx.tcon);
3508	if (rc)
3509		goto error;
3510
3511	free_xid(mnt_ctx.xid);
3512	return rc;
3513
3514error:
3515	dfs_cache_put_refsrv_sessions(&mnt_ctx.mount_id);
3516	kfree(mnt_ctx.origin_fullpath);
3517	kfree(mnt_ctx.leaf_fullpath);
3518	cifs_mount_put_conns(&mnt_ctx);
3519	return rc;
3520}
3521#else
3522int cifs_mount(struct cifs_sb_info *cifs_sb, struct smb3_fs_context *ctx)
3523{
3524	int rc = 0;
3525	struct cifs_mount_ctx mnt_ctx = { .cifs_sb = cifs_sb, .fs_ctx = ctx, };
3526
3527	rc = cifs_mount_get_session(&mnt_ctx);
3528	if (rc)
3529		goto error;
3530
3531	rc = cifs_mount_get_tcon(&mnt_ctx);
3532	if (rc)
3533		goto error;
3534
3535	rc = cifs_is_path_remote(&mnt_ctx);
3536	if (rc == -EREMOTE)
3537		rc = -EOPNOTSUPP;
3538	if (rc)
3539		goto error;
3540
3541	rc = mount_setup_tlink(cifs_sb, mnt_ctx.ses, mnt_ctx.tcon);
3542	if (rc)
3543		goto error;
3544
3545	free_xid(mnt_ctx.xid);
3546	return rc;
3547
3548error:
3549	cifs_mount_put_conns(&mnt_ctx);
3550	return rc;
3551}
3552#endif
3553
3554/*
3555 * Issue a TREE_CONNECT request.
 
3556 */
3557int
3558CIFSTCon(const unsigned int xid, struct cifs_ses *ses,
3559	 const char *tree, struct cifs_tcon *tcon,
3560	 const struct nls_table *nls_codepage)
3561{
3562	struct smb_hdr *smb_buffer;
3563	struct smb_hdr *smb_buffer_response;
3564	TCONX_REQ *pSMB;
3565	TCONX_RSP *pSMBr;
3566	unsigned char *bcc_ptr;
3567	int rc = 0;
3568	int length;
3569	__u16 bytes_left, count;
3570
3571	if (ses == NULL)
3572		return -EIO;
3573
3574	smb_buffer = cifs_buf_get();
3575	if (smb_buffer == NULL)
3576		return -ENOMEM;
3577
3578	smb_buffer_response = smb_buffer;
3579
3580	header_assemble(smb_buffer, SMB_COM_TREE_CONNECT_ANDX,
3581			NULL /*no tid */ , 4 /*wct */ );
3582
3583	smb_buffer->Mid = get_next_mid(ses->server);
3584	smb_buffer->Uid = ses->Suid;
3585	pSMB = (TCONX_REQ *) smb_buffer;
3586	pSMBr = (TCONX_RSP *) smb_buffer_response;
3587
3588	pSMB->AndXCommand = 0xFF;
3589	pSMB->Flags = cpu_to_le16(TCON_EXTENDED_SECINFO);
3590	bcc_ptr = &pSMB->Password[0];
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
3591
3592	pSMB->PasswordLength = cpu_to_le16(1);	/* minimum */
3593	*bcc_ptr = 0; /* password is null byte */
3594	bcc_ptr++;              /* skip password */
3595	/* already aligned so no need to do it below */
 
 
 
3596
3597	if (ses->server->sign)
 
3598		smb_buffer->Flags2 |= SMBFLG2_SECURITY_SIGNATURE;
3599
3600	if (ses->capabilities & CAP_STATUS32) {
3601		smb_buffer->Flags2 |= SMBFLG2_ERR_STATUS;
3602	}
3603	if (ses->capabilities & CAP_DFS) {
3604		smb_buffer->Flags2 |= SMBFLG2_DFS;
3605	}
3606	if (ses->capabilities & CAP_UNICODE) {
3607		smb_buffer->Flags2 |= SMBFLG2_UNICODE;
3608		length =
3609		    cifs_strtoUTF16((__le16 *) bcc_ptr, tree,
3610			6 /* max utf8 char length in bytes */ *
3611			(/* server len*/ + 256 /* share len */), nls_codepage);
3612		bcc_ptr += 2 * length;	/* convert num 16 bit words to bytes */
3613		bcc_ptr += 2;	/* skip trailing null */
3614	} else {		/* ASCII */
3615		strcpy(bcc_ptr, tree);
3616		bcc_ptr += strlen(tree) + 1;
3617	}
3618	strcpy(bcc_ptr, "?????");
3619	bcc_ptr += strlen("?????");
3620	bcc_ptr += 1;
3621	count = bcc_ptr - &pSMB->Password[0];
3622	be32_add_cpu(&pSMB->hdr.smb_buf_length, count);
 
3623	pSMB->ByteCount = cpu_to_le16(count);
3624
3625	rc = SendReceive(xid, ses, smb_buffer, smb_buffer_response, &length,
3626			 0);
3627
3628	/* above now done in SendReceive */
3629	if (rc == 0) {
3630		bool is_unicode;
3631
 
 
3632		tcon->tid = smb_buffer_response->Tid;
3633		bcc_ptr = pByteArea(smb_buffer_response);
3634		bytes_left = get_bcc(smb_buffer_response);
3635		length = strnlen(bcc_ptr, bytes_left - 2);
3636		if (smb_buffer->Flags2 & SMBFLG2_UNICODE)
3637			is_unicode = true;
3638		else
3639			is_unicode = false;
3640
3641
3642		/* skip service field (NB: this field is always ASCII) */
3643		if (length == 3) {
3644			if ((bcc_ptr[0] == 'I') && (bcc_ptr[1] == 'P') &&
3645			    (bcc_ptr[2] == 'C')) {
3646				cifs_dbg(FYI, "IPC connection\n");
3647				tcon->ipc = true;
3648				tcon->pipe = true;
3649			}
3650		} else if (length == 2) {
3651			if ((bcc_ptr[0] == 'A') && (bcc_ptr[1] == ':')) {
3652				/* the most common case */
3653				cifs_dbg(FYI, "disk share connection\n");
3654			}
3655		}
3656		bcc_ptr += length + 1;
3657		bytes_left -= (length + 1);
3658		strscpy(tcon->tree_name, tree, sizeof(tcon->tree_name));
3659
3660		/* mostly informational -- no need to fail on error here */
3661		kfree(tcon->nativeFileSystem);
3662		tcon->nativeFileSystem = cifs_strndup_from_utf16(bcc_ptr,
3663						      bytes_left, is_unicode,
3664						      nls_codepage);
3665
3666		cifs_dbg(FYI, "nativeFileSystem=%s\n", tcon->nativeFileSystem);
3667
3668		if ((smb_buffer_response->WordCount == 3) ||
3669			 (smb_buffer_response->WordCount == 7))
3670			/* field is in same location */
3671			tcon->Flags = le16_to_cpu(pSMBr->OptionalSupport);
3672		else
3673			tcon->Flags = 0;
3674		cifs_dbg(FYI, "Tcon flags: 0x%x\n", tcon->Flags);
 
 
 
3675	}
3676
3677	cifs_buf_release(smb_buffer);
3678	return rc;
3679}
3680
3681static void delayed_free(struct rcu_head *p)
3682{
3683	struct cifs_sb_info *cifs_sb = container_of(p, struct cifs_sb_info, rcu);
3684
3685	unload_nls(cifs_sb->local_nls);
3686	smb3_cleanup_fs_context(cifs_sb->ctx);
3687	kfree(cifs_sb);
3688}
3689
3690void
3691cifs_umount(struct cifs_sb_info *cifs_sb)
3692{
3693	struct rb_root *root = &cifs_sb->tlink_tree;
3694	struct rb_node *node;
3695	struct tcon_link *tlink;
3696
3697	cancel_delayed_work_sync(&cifs_sb->prune_tlinks);
3698
3699	spin_lock(&cifs_sb->tlink_tree_lock);
3700	while ((node = rb_first(root))) {
3701		tlink = rb_entry(node, struct tcon_link, tl_rbnode);
3702		cifs_get_tlink(tlink);
3703		clear_bit(TCON_LINK_IN_TREE, &tlink->tl_flags);
3704		rb_erase(node, root);
3705
3706		spin_unlock(&cifs_sb->tlink_tree_lock);
3707		cifs_put_tlink(tlink);
3708		spin_lock(&cifs_sb->tlink_tree_lock);
3709	}
3710	spin_unlock(&cifs_sb->tlink_tree_lock);
3711
3712	kfree(cifs_sb->prepath);
3713#ifdef CONFIG_CIFS_DFS_UPCALL
3714	dfs_cache_put_refsrv_sessions(&cifs_sb->dfs_mount_id);
3715#endif
3716	call_rcu(&cifs_sb->rcu, delayed_free);
3717}
3718
3719int
3720cifs_negotiate_protocol(const unsigned int xid, struct cifs_ses *ses,
3721			struct TCP_Server_Info *server)
3722{
3723	int rc = 0;
3724
3725	if (!server->ops->need_neg || !server->ops->negotiate)
3726		return -ENOSYS;
3727
3728	/* only send once per connect */
3729	spin_lock(&server->srv_lock);
3730	if (!server->ops->need_neg(server) ||
3731	    server->tcpStatus != CifsNeedNegotiate) {
3732		spin_unlock(&server->srv_lock);
3733		return 0;
 
 
 
 
 
 
 
3734	}
3735	server->tcpStatus = CifsInNegotiate;
3736	spin_unlock(&server->srv_lock);
3737
3738	rc = server->ops->negotiate(xid, ses, server);
3739	if (rc == 0) {
3740		spin_lock(&server->srv_lock);
3741		if (server->tcpStatus == CifsInNegotiate)
3742			server->tcpStatus = CifsGood;
3743		else
3744			rc = -EHOSTDOWN;
3745		spin_unlock(&server->srv_lock);
3746	} else {
3747		spin_lock(&server->srv_lock);
3748		if (server->tcpStatus == CifsInNegotiate)
3749			server->tcpStatus = CifsNeedNegotiate;
3750		spin_unlock(&server->srv_lock);
3751	}
3752
3753	return rc;
3754}
3755
3756int
3757cifs_setup_session(const unsigned int xid, struct cifs_ses *ses,
3758		   struct TCP_Server_Info *server,
3759		   struct nls_table *nls_info)
3760{
3761	int rc = -ENOSYS;
3762	struct sockaddr_in6 *addr6 = (struct sockaddr_in6 *)&server->dstaddr;
3763	struct sockaddr_in *addr = (struct sockaddr_in *)&server->dstaddr;
3764	bool is_binding = false;
3765
3766	spin_lock(&ses->ses_lock);
3767	if (server->dstaddr.ss_family == AF_INET6)
3768		scnprintf(ses->ip_addr, sizeof(ses->ip_addr), "%pI6", &addr6->sin6_addr);
3769	else
3770		scnprintf(ses->ip_addr, sizeof(ses->ip_addr), "%pI4", &addr->sin_addr);
3771
3772	if (ses->ses_status != SES_GOOD &&
3773	    ses->ses_status != SES_NEW &&
3774	    ses->ses_status != SES_NEED_RECON) {
3775		spin_unlock(&ses->ses_lock);
3776		return 0;
3777	}
3778
3779	/* only send once per connect */
3780	spin_lock(&ses->chan_lock);
3781	if (CIFS_ALL_CHANS_GOOD(ses) ||
3782	    cifs_chan_in_reconnect(ses, server)) {
3783		spin_unlock(&ses->chan_lock);
3784		spin_unlock(&ses->ses_lock);
3785		return 0;
3786	}
3787	is_binding = !CIFS_ALL_CHANS_NEED_RECONNECT(ses);
3788	cifs_chan_set_in_reconnect(ses, server);
3789	spin_unlock(&ses->chan_lock);
3790
3791	if (!is_binding)
3792		ses->ses_status = SES_IN_SETUP;
3793	spin_unlock(&ses->ses_lock);
3794
3795	if (!is_binding) {
3796		ses->capabilities = server->capabilities;
3797		if (!linuxExtEnabled)
3798			ses->capabilities &= (~server->vals->cap_unix);
3799
3800		if (ses->auth_key.response) {
3801			cifs_dbg(FYI, "Free previous auth_key.response = %p\n",
3802				 ses->auth_key.response);
3803			kfree_sensitive(ses->auth_key.response);
3804			ses->auth_key.response = NULL;
3805			ses->auth_key.len = 0;
3806		}
 
 
 
 
 
 
 
3807	}
3808
3809	cifs_dbg(FYI, "Security Mode: 0x%x Capabilities: 0x%x TimeAdjust: %d\n",
3810		 server->sec_mode, server->capabilities, server->timeAdj);
3811
3812	if (server->ops->sess_setup)
3813		rc = server->ops->sess_setup(xid, ses, server, nls_info);
3814
3815	if (rc) {
3816		cifs_server_dbg(VFS, "Send error in SessSetup = %d\n", rc);
3817		spin_lock(&ses->ses_lock);
3818		if (ses->ses_status == SES_IN_SETUP)
3819			ses->ses_status = SES_NEED_RECON;
3820		spin_lock(&ses->chan_lock);
3821		cifs_chan_clear_in_reconnect(ses, server);
3822		spin_unlock(&ses->chan_lock);
3823		spin_unlock(&ses->ses_lock);
3824	} else {
3825		spin_lock(&ses->ses_lock);
3826		if (ses->ses_status == SES_IN_SETUP)
3827			ses->ses_status = SES_GOOD;
3828		spin_lock(&ses->chan_lock);
3829		cifs_chan_clear_in_reconnect(ses, server);
3830		cifs_chan_clear_need_reconnect(ses, server);
3831		spin_unlock(&ses->chan_lock);
3832		spin_unlock(&ses->ses_lock);
3833	}
3834
3835	return rc;
3836}
3837
3838static int
3839cifs_set_vol_auth(struct smb3_fs_context *ctx, struct cifs_ses *ses)
3840{
3841	ctx->sectype = ses->sectype;
3842
3843	/* krb5 is special, since we don't need username or pw */
3844	if (ctx->sectype == Kerberos)
3845		return 0;
3846
3847	return cifs_set_cifscreds(ctx, ses);
3848}
3849
3850static struct cifs_tcon *
3851cifs_construct_tcon(struct cifs_sb_info *cifs_sb, kuid_t fsuid)
3852{
3853	int rc;
3854	struct cifs_tcon *master_tcon = cifs_sb_master_tcon(cifs_sb);
3855	struct cifs_ses *ses;
3856	struct cifs_tcon *tcon = NULL;
3857	struct smb3_fs_context *ctx;
 
 
 
 
 
 
 
 
 
3858
3859	ctx = kzalloc(sizeof(*ctx), GFP_KERNEL);
3860	if (ctx == NULL)
3861		return ERR_PTR(-ENOMEM);
3862
3863	ctx->local_nls = cifs_sb->local_nls;
3864	ctx->linux_uid = fsuid;
3865	ctx->cred_uid = fsuid;
3866	ctx->UNC = master_tcon->tree_name;
3867	ctx->retry = master_tcon->retry;
3868	ctx->nocase = master_tcon->nocase;
3869	ctx->nohandlecache = master_tcon->nohandlecache;
3870	ctx->local_lease = master_tcon->local_lease;
3871	ctx->no_lease = master_tcon->no_lease;
3872	ctx->resilient = master_tcon->use_resilient;
3873	ctx->persistent = master_tcon->use_persistent;
3874	ctx->handle_timeout = master_tcon->handle_timeout;
3875	ctx->no_linux_ext = !master_tcon->unix_ext;
3876	ctx->linux_ext = master_tcon->posix_extensions;
3877	ctx->sectype = master_tcon->ses->sectype;
3878	ctx->sign = master_tcon->ses->sign;
3879	ctx->seal = master_tcon->seal;
3880	ctx->witness = master_tcon->use_witness;
3881
3882	rc = cifs_set_vol_auth(ctx, master_tcon->ses);
3883	if (rc) {
3884		tcon = ERR_PTR(rc);
3885		goto out;
3886	}
3887
3888	/* get a reference for the same TCP session */
3889	spin_lock(&cifs_tcp_ses_lock);
3890	++master_tcon->ses->server->srv_count;
3891	spin_unlock(&cifs_tcp_ses_lock);
3892
3893	ses = cifs_get_smb_ses(master_tcon->ses->server, ctx);
3894	if (IS_ERR(ses)) {
3895		tcon = (struct cifs_tcon *)ses;
3896		cifs_put_tcp_session(master_tcon->ses->server, 0);
3897		goto out;
3898	}
3899
3900	tcon = cifs_get_tcon(ses, ctx);
3901	if (IS_ERR(tcon)) {
3902		cifs_put_smb_ses(ses);
3903		goto out;
3904	}
3905
3906#ifdef CONFIG_CIFS_ALLOW_INSECURE_LEGACY
3907	if (cap_unix(ses))
3908		reset_cifs_unix_caps(0, tcon, NULL, ctx);
3909#endif /* CONFIG_CIFS_ALLOW_INSECURE_LEGACY */
3910
3911out:
3912	kfree(ctx->username);
3913	kfree_sensitive(ctx->password);
3914	kfree(ctx);
3915
3916	return tcon;
3917}
3918
3919struct cifs_tcon *
3920cifs_sb_master_tcon(struct cifs_sb_info *cifs_sb)
3921{
3922	return tlink_tcon(cifs_sb_master_tlink(cifs_sb));
3923}
3924
 
 
 
 
 
 
 
3925/* find and return a tlink with given uid */
3926static struct tcon_link *
3927tlink_rb_search(struct rb_root *root, kuid_t uid)
3928{
3929	struct rb_node *node = root->rb_node;
3930	struct tcon_link *tlink;
3931
3932	while (node) {
3933		tlink = rb_entry(node, struct tcon_link, tl_rbnode);
3934
3935		if (uid_gt(tlink->tl_uid, uid))
3936			node = node->rb_left;
3937		else if (uid_lt(tlink->tl_uid, uid))
3938			node = node->rb_right;
3939		else
3940			return tlink;
3941	}
3942	return NULL;
3943}
3944
3945/* insert a tcon_link into the tree */
3946static void
3947tlink_rb_insert(struct rb_root *root, struct tcon_link *new_tlink)
3948{
3949	struct rb_node **new = &(root->rb_node), *parent = NULL;
3950	struct tcon_link *tlink;
3951
3952	while (*new) {
3953		tlink = rb_entry(*new, struct tcon_link, tl_rbnode);
3954		parent = *new;
3955
3956		if (uid_gt(tlink->tl_uid, new_tlink->tl_uid))
3957			new = &((*new)->rb_left);
3958		else
3959			new = &((*new)->rb_right);
3960	}
3961
3962	rb_link_node(&new_tlink->tl_rbnode, parent, new);
3963	rb_insert_color(&new_tlink->tl_rbnode, root);
3964}
3965
3966/*
3967 * Find or construct an appropriate tcon given a cifs_sb and the fsuid of the
3968 * current task.
3969 *
3970 * If the superblock doesn't refer to a multiuser mount, then just return
3971 * the master tcon for the mount.
3972 *
3973 * First, search the rbtree for an existing tcon for this fsuid. If one
3974 * exists, then check to see if it's pending construction. If it is then wait
3975 * for construction to complete. Once it's no longer pending, check to see if
3976 * it failed and either return an error or retry construction, depending on
3977 * the timeout.
3978 *
3979 * If one doesn't exist then insert a new tcon_link struct into the tree and
3980 * try to construct a new one.
3981 */
3982struct tcon_link *
3983cifs_sb_tlink(struct cifs_sb_info *cifs_sb)
3984{
3985	int ret;
3986	kuid_t fsuid = current_fsuid();
3987	struct tcon_link *tlink, *newtlink;
3988
3989	if (!(cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MULTIUSER))
3990		return cifs_get_tlink(cifs_sb_master_tlink(cifs_sb));
3991
3992	spin_lock(&cifs_sb->tlink_tree_lock);
3993	tlink = tlink_rb_search(&cifs_sb->tlink_tree, fsuid);
3994	if (tlink)
3995		cifs_get_tlink(tlink);
3996	spin_unlock(&cifs_sb->tlink_tree_lock);
3997
3998	if (tlink == NULL) {
3999		newtlink = kzalloc(sizeof(*tlink), GFP_KERNEL);
4000		if (newtlink == NULL)
4001			return ERR_PTR(-ENOMEM);
4002		newtlink->tl_uid = fsuid;
4003		newtlink->tl_tcon = ERR_PTR(-EACCES);
4004		set_bit(TCON_LINK_PENDING, &newtlink->tl_flags);
4005		set_bit(TCON_LINK_IN_TREE, &newtlink->tl_flags);
4006		cifs_get_tlink(newtlink);
4007
4008		spin_lock(&cifs_sb->tlink_tree_lock);
4009		/* was one inserted after previous search? */
4010		tlink = tlink_rb_search(&cifs_sb->tlink_tree, fsuid);
4011		if (tlink) {
4012			cifs_get_tlink(tlink);
4013			spin_unlock(&cifs_sb->tlink_tree_lock);
4014			kfree(newtlink);
4015			goto wait_for_construction;
4016		}
4017		tlink = newtlink;
4018		tlink_rb_insert(&cifs_sb->tlink_tree, tlink);
4019		spin_unlock(&cifs_sb->tlink_tree_lock);
4020	} else {
4021wait_for_construction:
4022		ret = wait_on_bit(&tlink->tl_flags, TCON_LINK_PENDING,
 
4023				  TASK_INTERRUPTIBLE);
4024		if (ret) {
4025			cifs_put_tlink(tlink);
4026			return ERR_PTR(-ERESTARTSYS);
4027		}
4028
4029		/* if it's good, return it */
4030		if (!IS_ERR(tlink->tl_tcon))
4031			return tlink;
4032
4033		/* return error if we tried this already recently */
4034		if (time_before(jiffies, tlink->tl_time + TLINK_ERROR_EXPIRE)) {
4035			cifs_put_tlink(tlink);
4036			return ERR_PTR(-EACCES);
4037		}
4038
4039		if (test_and_set_bit(TCON_LINK_PENDING, &tlink->tl_flags))
4040			goto wait_for_construction;
4041	}
4042
4043	tlink->tl_tcon = cifs_construct_tcon(cifs_sb, fsuid);
4044	clear_bit(TCON_LINK_PENDING, &tlink->tl_flags);
4045	wake_up_bit(&tlink->tl_flags, TCON_LINK_PENDING);
4046
4047	if (IS_ERR(tlink->tl_tcon)) {
4048		cifs_put_tlink(tlink);
4049		return ERR_PTR(-EACCES);
4050	}
4051
4052	return tlink;
4053}
4054
4055/*
4056 * periodic workqueue job that scans tcon_tree for a superblock and closes
4057 * out tcons.
4058 */
4059static void
4060cifs_prune_tlinks(struct work_struct *work)
4061{
4062	struct cifs_sb_info *cifs_sb = container_of(work, struct cifs_sb_info,
4063						    prune_tlinks.work);
4064	struct rb_root *root = &cifs_sb->tlink_tree;
4065	struct rb_node *node;
4066	struct rb_node *tmp;
4067	struct tcon_link *tlink;
4068
4069	/*
4070	 * Because we drop the spinlock in the loop in order to put the tlink
4071	 * it's not guarded against removal of links from the tree. The only
4072	 * places that remove entries from the tree are this function and
4073	 * umounts. Because this function is non-reentrant and is canceled
4074	 * before umount can proceed, this is safe.
4075	 */
4076	spin_lock(&cifs_sb->tlink_tree_lock);
4077	node = rb_first(root);
4078	while (node != NULL) {
4079		tmp = node;
4080		node = rb_next(tmp);
4081		tlink = rb_entry(tmp, struct tcon_link, tl_rbnode);
4082
4083		if (test_bit(TCON_LINK_MASTER, &tlink->tl_flags) ||
4084		    atomic_read(&tlink->tl_count) != 0 ||
4085		    time_after(tlink->tl_time + TLINK_IDLE_EXPIRE, jiffies))
4086			continue;
4087
4088		cifs_get_tlink(tlink);
4089		clear_bit(TCON_LINK_IN_TREE, &tlink->tl_flags);
4090		rb_erase(tmp, root);
4091
4092		spin_unlock(&cifs_sb->tlink_tree_lock);
4093		cifs_put_tlink(tlink);
4094		spin_lock(&cifs_sb->tlink_tree_lock);
4095	}
4096	spin_unlock(&cifs_sb->tlink_tree_lock);
4097
4098	queue_delayed_work(cifsiod_wq, &cifs_sb->prune_tlinks,
4099				TLINK_IDLE_EXPIRE);
4100}
4101
4102#ifndef CONFIG_CIFS_DFS_UPCALL
4103int cifs_tree_connect(const unsigned int xid, struct cifs_tcon *tcon, const struct nls_table *nlsc)
4104{
4105	int rc;
4106	const struct smb_version_operations *ops = tcon->ses->server->ops;
4107
4108	/* only send once per connect */
4109	spin_lock(&tcon->tc_lock);
4110	if (tcon->ses->ses_status != SES_GOOD ||
4111	    (tcon->status != TID_NEW &&
4112	    tcon->status != TID_NEED_TCON)) {
4113		spin_unlock(&tcon->tc_lock);
4114		return 0;
4115	}
4116	tcon->status = TID_IN_TCON;
4117	spin_unlock(&tcon->tc_lock);
4118
4119	rc = ops->tree_connect(xid, tcon->ses, tcon->tree_name, tcon, nlsc);
4120	if (rc) {
4121		spin_lock(&tcon->tc_lock);
4122		if (tcon->status == TID_IN_TCON)
4123			tcon->status = TID_NEED_TCON;
4124		spin_unlock(&tcon->tc_lock);
4125	} else {
4126		spin_lock(&tcon->tc_lock);
4127		if (tcon->status == TID_IN_TCON)
4128			tcon->status = TID_GOOD;
4129		tcon->need_reconnect = false;
4130		spin_unlock(&tcon->tc_lock);
4131	}
4132
4133	return rc;
4134}
4135#endif